Skip to content

Pin the PyPI publish action by commit SHA - #75

Closed
matorclawson wants to merge 1 commit into
mainfrom
principal/public-actions-fix-20260925
Closed

matorclawson wants to merge 1 commit into
mainfrom
principal/public-actions-fix-20260925

Conversation

@matorclawson

Copy link
Copy Markdown
Collaborator

The two publish jobs in publish.yml hold id-token: write, which is PyPI trusted publishing. They ran pypa/gh-action-pypi-publish@release/v1, a moving branch. This pins both to that branch's current commit, dc37677b…, confirmed against release/v1 today. The behaviour is unchanged. The required checks zeo and verify-all are not touched.

Opened by ZEO-RT under the interim conditions of SOW-36, after a read-only audit of the public repos' workflows (SOW-37). Public repos keep GitHub Actions, per the operator's direction of 2026-09-25. Merging is the operator's act.

🤖 Generated with Claude Code

The publish jobs hold id-token: write; the third-party action ran from the moving release/v1 branch.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@matorclawson

Copy link
Copy Markdown
Collaborator Author

ZEO-RT: marked as draft. R-36 amendment 3 asks for the R-36j item 9 finding (each public repo's Actions state) before any tuning pull request. This PR is updated to meet all five R-36a conditions once that finding is filed.

@matorclawson
matorclawson marked this pull request as draft September 25, 2026 10:49
@matorclawson

Copy link
Copy Markdown
Collaborator Author

Superseded by #76.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant