Skip to content
This repository was archived by the owner on May 20, 2025. It is now read-only.

Commit 11e1dde

Browse files
committed
chore(ci): gha-update, small cleanup
1 parent db093f5 commit 11e1dde

File tree

3 files changed

+12
-6
lines changed

3 files changed

+12
-6
lines changed

.github/workflows/ci.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,13 @@ on:
66
- main
77
pull_request:
88

9+
permissions: {}
10+
911
jobs:
1012
lint:
1113
runs-on: ubuntu-latest
1214
steps:
13-
- uses: actions/checkout@v4
15+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1416
with:
1517
persist-credentials: false
1618

@@ -25,7 +27,7 @@ jobs:
2527
test:
2628
runs-on: ubuntu-latest
2729
steps:
28-
- uses: actions/checkout@v4
30+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2931
with:
3032
persist-credentials: false
3133

.github/workflows/release.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,11 +5,13 @@ on:
55

66
name: release
77

8+
permissions: {}
9+
810
jobs:
911
release:
1012
runs-on: ubuntu-latest
1113
steps:
12-
- uses: actions/checkout@v4
14+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1315
with:
1416
persist-credentials: false
1517

.github/workflows/zizmor.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ on:
66
pull_request:
77
branches: ["**"]
88

9+
permissions: {}
10+
911
jobs:
1012
zizmor:
1113
name: zizmor latest via Cargo
@@ -17,20 +19,20 @@ jobs:
1719
actions: read
1820
steps:
1921
- name: Checkout repository
20-
uses: actions/checkout@v4
22+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2123
with:
2224
persist-credentials: false
2325

2426
- name: Install the latest version of uv
25-
uses: astral-sh/setup-uv@v5
27+
uses: astral-sh/setup-uv@6b9c6063abd6010835644d4c2e1bef4cf5cd0fca # v6.0.1
2628

2729
- name: Run zizmor 🌈
2830
run: uvx zizmor --format sarif . > results.sarif
2931
env:
3032
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
3133

3234
- name: Upload SARIF file
33-
uses: github/codeql-action/upload-sarif@v3
35+
uses: github/codeql-action/upload-sarif@60168efe1c415ce0f5521ea06d5c2062adbeed1b # v3.28.17
3436
with:
3537
sarif_file: results.sarif
3638
category: zizmor

0 commit comments

Comments
 (0)