Skip to content

Commit d0df32f

Browse files
authored
Address zizmor errors and warnings (#14)
1 parent 990662d commit d0df32f

2 files changed

Lines changed: 15 additions & 8 deletions

File tree

.github/workflows/build.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,16 @@ on:
66
pull_request:
77
branches: [ main ]
88

9+
permissions:
10+
contents: read
11+
912
jobs:
1013
build:
1114
runs-on: ubuntu-latest
1215
steps:
1316
- uses: actions/checkout@v3
17+
with:
18+
persist-credentials: false
1419
- uses: actions/setup-python@v5
1520
with:
1621
python-version: 3.12

.github/workflows/release.yml

Lines changed: 10 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -5,15 +5,15 @@ on:
55
tags:
66
- 'v*'
77

8-
permissions:
9-
contents: write
10-
id-token: write
11-
128
jobs:
139
release:
1410
runs-on: ubuntu-latest
11+
permissions:
12+
contents: write
1513
steps:
1614
- uses: actions/checkout@v3
15+
with:
16+
persist-credentials: false
1717
- uses: actions/setup-python@v5
1818
with:
1919
python-version: 3.12
@@ -32,7 +32,7 @@ jobs:
3232
draft: false
3333
prerelease: false
3434
- name: Upload release artifacts
35-
uses: korniltsev/actions-upload-release-asset@v1
35+
uses: korniltsev/actions-upload-release-asset@32f18be3a7dab6873e1d27e3aee2e0fec3620d5d # v1
3636
env:
3737
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
3838
with:
@@ -41,23 +41,25 @@ jobs:
4141
publish:
4242
needs: release
4343
runs-on: ubuntu-latest
44+
permissions:
45+
id-token: write
4446
steps:
45-
- uses: robinraju/release-downloader@v1.4
47+
- uses: robinraju/release-downloader@ed86e52bc497d1185844fc28454c5999aaed2fa5 # v1.4
4648
with:
4749
tag: ${{ github.ref_name }}
4850
fileName: "*"
4951
tarBall: false
5052
zipBall: false
5153
out-file-path: "dist"
5254
token: ${{ secrets.GITHUB_TOKEN }}
53-
- uses: grafana/shared-workflows/actions/get-vault-secrets@main
55+
- uses: grafana/shared-workflows/actions/get-vault-secrets@974c33049d0967c5c9cfc249fe675daf341dc78f
5456
with:
5557
vault_instance: dev
5658
# Secrets placed in the ci/repo/grafana/otel-profiling-python/ path in Vault
5759
repo_secrets: |
5860
PYPI_API_TOKEN=publishing:pypi_api_key
5961
- name: Publish a Python distribution to PyPI
60-
uses: pypa/gh-action-pypi-publish@release/v1
62+
uses: pypa/gh-action-pypi-publish@76f52bc884231f62b9a034ebfe128415bbaabdfc # v1.12.4
6163
with:
6264
user: __token__
6365
password: ${{ env.PYPI_API_TOKEN }}

0 commit comments

Comments
 (0)