Skip to content

Commit db7e09e

Browse files
committed
ci: pin non-gh, non-hynek, non-pypa uses
1 parent 2189691 commit db7e09e

3 files changed

Lines changed: 13 additions & 2 deletions

File tree

.github/workflows/ci.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -228,6 +228,7 @@ jobs:
228228

229229
steps:
230230
- name: Decide whether the needed jobs succeeded or failed
231-
uses: re-actors/alls-green@release/v1
231+
# v1.2.2
232+
uses: re-actors/alls-green@05ac9388f0aebcb5727afa17fcccfecd6f8ec5fe
232233
with:
233234
jobs: ${{ toJSON(needs) }}

.github/workflows/codspeed.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,8 @@ jobs:
3939
- uses: hynek/setup-cached-uv@v2
4040

4141
- name: Run CodSpeed benchmarks
42-
uses: CodSpeedHQ/action@v3
42+
# v3.5.0
43+
uses: CodSpeedHQ/action@0010eb0ca6e89b80c88e8edaaa07cfe5f3e6664d
4344
with:
4445
token: ${{ secrets.CODSPEED_TOKEN }}
4546
run: uvx --with tox-uv tox run -e codspeed

zizmor.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
rules:
3+
unpinned-uses:
4+
config:
5+
policies:
6+
"actions/*": ref-pin
7+
"github/*": ref-pin
8+
"hynek/*": ref-pin
9+
"pypa/*": ref-pin

0 commit comments

Comments
 (0)