Skip to content

Commit acbbc3b

Browse files
committed
ci: add permissions blocks and pin action SHAs
1 parent 372f88c commit acbbc3b

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

.github/workflows/release-please.yml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,21 +5,25 @@ on:
55
branches:
66
- main
77

8+
permissions: {}
9+
810
jobs:
911
release-please:
1012
runs-on: ubuntu-latest
13+
permissions:
14+
contents: read
1115
outputs:
1216
release_created: ${{ steps.release.outputs.release_created }}
1317
tag_name: ${{ steps.release.outputs.tag_name }}
1418
steps:
1519
- name: Generate GitHub App Token
1620
id: app-token
17-
uses: actions/create-github-app-token@v1
21+
uses: actions/create-github-app-token@d72941d797fd3113feb6b93fd0dec494b13a2547 # v1
1822
with:
1923
app-id: ${{ secrets.RELEASE_BOT_APP_ID }}
2024
private-key: ${{ secrets.RELEASE_BOT_PRIVATE_KEY }}
2125

22-
- uses: googleapis/release-please-action@v4
26+
- uses: googleapis/release-please-action@c3fc4de07084f75a2b61a5b933069bda6edf3d5c # v4
2327
id: release
2428
with:
2529
token: ${{ steps.app-token.outputs.token }}
@@ -49,4 +53,4 @@ jobs:
4953
uses: descope/.github/.github/actions/python/poetry/build@main
5054

5155
- name: Publish to PyPI
52-
uses: pypa/gh-action-pypi-publish@release/v1
56+
uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # release/v1

0 commit comments

Comments
 (0)