Skip to content

Commit 86d4374

Browse files
Harden default permissions of GH actions ( - Fixes #39 and #40 - )
* Harden default permissions of GH actions ( - Fixes #39 - ) * Bump version of GH checkout action ( - WIP #40 / WIP #44 - ) * Bump version of GH setup-pytho action ( - Fixes #44 - ) * Simplify eager triggers of GH actions ( - Resolves #42 - )
1 parent 4dca608 commit 86d4374

File tree

3 files changed

+18
-11
lines changed

3 files changed

+18
-11
lines changed

.github/workflows/Labeler.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ on:
55
branches: [ master, stable ]
66

77
# Declare default permissions as none.
8-
permissions: none
8+
permissions: {}
99

1010
jobs:
1111
triage:

.github/workflows/Tests.yml

Lines changed: 16 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,13 @@ on:
66
- stable
77
tags:
88
- v*
9+
pull_request:
10+
types:
11+
- opened
12+
- edited
13+
- reopened
14+
- synchronize
15+
- ready_for_review
916

1017
# Declare default permissions as read only.
1118
permissions: read-all
@@ -21,7 +28,7 @@ jobs:
2128
LANG: "en_US.UTF-8"
2229
steps:
2330
- uses: actions/checkout@v4
24-
- uses: actions/setup-python@v4
31+
- uses: actions/setup-python@v5
2532
with:
2633
python-version: "3.12"
2734
- name: Pre-Clean
@@ -81,7 +88,7 @@ jobs:
8188
steps:
8289
- uses: actions/checkout@v4
8390
- name: Setup Python
84-
uses: actions/setup-python@v4
91+
uses: actions/setup-python@v5
8592
with:
8693
python-version: ${{ matrix.python-version }}
8794
- name: Setup dependencies
@@ -139,7 +146,7 @@ jobs:
139146
steps:
140147
- uses: actions/checkout@v4
141148
- name: Setup Python ${{ matrix.python-version }}
142-
uses: actions/setup-python@v4
149+
uses: actions/setup-python@v5
143150
with:
144151
python-version: ${{ matrix.python-version }}
145152
- name: Install dependencies for ${{ matrix.python-version }}
@@ -186,7 +193,7 @@ jobs:
186193
steps:
187194
- uses: actions/checkout@v4
188195
- name: Setup Python ${{ matrix.python-version }}
189-
uses: actions/setup-python@v4
196+
uses: actions/setup-python@v5
190197
with:
191198
python-version: ${{ matrix.python-version }}
192199
- name: Install dependencies for python ${{ matrix.python-version }} on ${{ matrix.os }}
@@ -268,9 +275,9 @@ jobs:
268275
CODECLIMATE_REPO_TOKEN: ${{ secrets.CODECLIMATE_TOKEN }}
269276
CC_TEST_REPORTER_ID: ${{ secrets.CC_TEST_REPORTER_ID }}
270277
steps:
271-
- uses: actions/checkout@v3
278+
- uses: actions/checkout@v4
272279
- name: Setup Python ${{ matrix.python-version }}
273-
uses: actions/setup-python@v4
280+
uses: actions/setup-python@v5
274281
with:
275282
python-version: ${{ matrix.python-version }}
276283
- name: Install dependencies for python ${{ matrix.python-version }} on ${{ matrix.os }}
@@ -345,7 +352,7 @@ jobs:
345352
steps:
346353
- uses: actions/checkout@v4
347354
- name: Setup Python
348-
uses: actions/setup-python@v4
355+
uses: actions/setup-python@v5
349356
with:
350357
python-version: "3.10"
351358
- name: Install dependencies for python Linters
@@ -391,7 +398,7 @@ jobs:
391398
steps:
392399
- uses: actions/checkout@v4
393400
- name: Setup Python ${{ matrix.python-version }}
394-
uses: actions/setup-python@v4
401+
uses: actions/setup-python@v5
395402
with:
396403
python-version: ${{ matrix.python-version }}
397404
- name: Install dependencies for python ${{ matrix.python-version }} on ${{ matrix.os }}
@@ -465,7 +472,7 @@ jobs:
465472
steps:
466473
- uses: actions/checkout@v4
467474
- name: Setup Python
468-
uses: actions/setup-python@v4
475+
uses: actions/setup-python@v5
469476
with:
470477
python-version: "3.10"
471478
- name: Install dependencies for Tox

.github/workflows/codeql-analysis.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141

4242
steps:
4343
- name: Checkout repository
44-
uses: actions/checkout@v4
44+
uses: actions/checkout@v4.1.7
4545

4646
# Initializes the CodeQL tools for scanning.
4747
- name: Initialize CodeQL

0 commit comments

Comments
 (0)