Skip to content

Resolve zizmor pedantic workflow findings#48

Merged
bboe merged 2 commits into
mainfrom
zizmor-pedantic
Jun 15, 2026
Merged

Resolve zizmor pedantic workflow findings#48
bboe merged 2 commits into
mainfrom
zizmor-pedantic

Conversation

@bboe

@bboe bboe commented Jun 15, 2026

Copy link
Copy Markdown
Member

Clears the remaining advisory zizmor --pedantic findings and bumps the praw-dev/.github reusable-workflow pins to v1.6.0.

Changes

  • ci.yml — workflow-level read-allcontents: read (excessive-permissions).
  • scorecard.ymlread-all{} (the analysis job keeps its own scoped grant), inline permission comments (undocumented-permissions), and a concurrency: group (concurrency-limits).
  • pypi.yml — inline comment on id-token: write (undocumented-permissions) and a concurrency: group (concurrency-limits).
  • dependabot.yml — add a 1-day cooldown (dependabot-cooldown).
  • Bump all praw-dev/.github reusable-workflow pins to v1.6.0.

Verified: zizmor --pedantic reports no findings and actionlint passes.

@bboe bboe merged commit e9667e0 into main Jun 15, 2026
9 checks passed
@bboe bboe deleted the zizmor-pedantic branch June 15, 2026 18:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant