Skip to content

chore: set explicit workflow permissions and pin down actions#2090

Merged
tdruez merged 4 commits intomainfrom
gh-workflows-security
Mar 11, 2026
Merged

chore: set explicit workflow permissions and pin down actions#2090
tdruez merged 4 commits intomainfrom
gh-workflows-security

Conversation

@tdruez
Copy link
Contributor

@tdruez tdruez commented Mar 11, 2026

Changes

  • Set explicit permissions
  • Pin down all external actions to an exact commit
  • Do not persist-credentials after the checkout
  • Refactor the publish PyPI workflow for trusted publishing

tdruez added 4 commits March 11, 2026 14:30
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
@tdruez tdruez changed the title Gh workflows security chore: set explicit workflow permissions and pin down actions Mar 11, 2026
@tdruez tdruez merged commit 876b113 into main Mar 11, 2026
13 checks passed
@tdruez tdruez deleted the gh-workflows-security branch March 11, 2026 02:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant