Skip to content

Commit 389e179

Browse files
committed
fix zizmor findings
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
1 parent 23d4d76 commit 389e179

File tree

8 files changed

+101
-69
lines changed

8 files changed

+101
-69
lines changed

.github/dependabot.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,21 @@ updates:
44
directory: "/"
55
schedule:
66
interval: "daily"
7+
cooldown:
8+
default-days: 2
9+
groups:
10+
crazy-max-dot-github:
11+
patterns:
12+
- "crazy-max/.github/*"
713
labels:
814
- "dependencies"
915
- "bot"
1016
- package-ecosystem: "npm"
1117
directory: "/"
1218
schedule:
1319
interval: "daily"
20+
cooldown:
21+
default-days: 2
1422
versioning-strategy: "increase"
1523
allow:
1624
- dependency-type: "production"

.github/workflows/ci.yml

Lines changed: 48 additions & 45 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
11
name: ci
22

3+
permissions:
4+
contents: read
5+
36
concurrency:
47
group: ${{ github.workflow }}-${{ github.ref }}
58
cancel-in-progress: true
@@ -31,7 +34,7 @@ jobs:
3134
steps:
3235
-
3336
name: Checkout
34-
uses: actions/checkout@v6
37+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3538
-
3639
name: Docker meta
3740
uses: ./
@@ -43,10 +46,10 @@ jobs:
4346
steps:
4447
-
4548
name: Checkout
46-
uses: actions/checkout@v6
49+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4750
-
4851
name: Set up Docker Buildx
49-
uses: docker/setup-buildx-action@v4
52+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
5053
with:
5154
version: ${{ env.BUILDX_VERSION }}
5255
driver: docker
@@ -80,10 +83,10 @@ jobs:
8083
steps:
8184
-
8285
name: Checkout
83-
uses: actions/checkout@v6
86+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
8487
-
8588
name: Set up Docker Buildx
86-
uses: docker/setup-buildx-action@v4
89+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
8790
with:
8891
version: ${{ env.BUILDX_VERSION }}
8992
driver: docker
@@ -116,10 +119,10 @@ jobs:
116119
steps:
117120
-
118121
name: Checkout
119-
uses: actions/checkout@v6
122+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
120123
-
121124
name: Set up Docker Buildx
122-
uses: docker/setup-buildx-action@v4
125+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
123126
with:
124127
version: ${{ env.BUILDX_VERSION }}
125128
driver: docker
@@ -150,10 +153,10 @@ jobs:
150153
steps:
151154
-
152155
name: Checkout
153-
uses: actions/checkout@v6
156+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
154157
-
155158
name: Set up Docker Buildx
156-
uses: docker/setup-buildx-action@v4
159+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
157160
with:
158161
version: ${{ env.BUILDX_VERSION }}
159162
driver: docker
@@ -181,10 +184,10 @@ jobs:
181184
steps:
182185
-
183186
name: Checkout
184-
uses: actions/checkout@v6
187+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
185188
-
186189
name: Set up Docker Buildx
187-
uses: docker/setup-buildx-action@v4
190+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
188191
with:
189192
version: ${{ env.BUILDX_VERSION }}
190193
driver: docker
@@ -204,10 +207,10 @@ jobs:
204207
steps:
205208
-
206209
name: Checkout
207-
uses: actions/checkout@v6
210+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
208211
-
209212
name: Set up Docker Buildx
210-
uses: docker/setup-buildx-action@v4
213+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
211214
with:
212215
version: ${{ env.BUILDX_VERSION }}
213216
driver: docker
@@ -225,10 +228,10 @@ jobs:
225228
steps:
226229
-
227230
name: Checkout
228-
uses: actions/checkout@v6
231+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
229232
-
230233
name: Set up Docker Buildx
231-
uses: docker/setup-buildx-action@v4
234+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
232235
with:
233236
version: ${{ env.BUILDX_VERSION }}
234237
driver: docker
@@ -255,10 +258,10 @@ jobs:
255258
steps:
256259
-
257260
name: Checkout
258-
uses: actions/checkout@v6
261+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
259262
-
260263
name: Set up Docker Buildx
261-
uses: docker/setup-buildx-action@v4
264+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
262265
with:
263266
version: ${{ env.BUILDX_VERSION }}
264267
driver: docker
@@ -285,10 +288,10 @@ jobs:
285288
steps:
286289
-
287290
name: Checkout
288-
uses: actions/checkout@v6
291+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
289292
-
290293
name: Set up Docker Buildx
291-
uses: docker/setup-buildx-action@v4
294+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
292295
with:
293296
version: ${{ env.BUILDX_VERSION }}
294297
driver: docker
@@ -314,16 +317,16 @@ jobs:
314317
runs-on: ubuntu-latest
315318
services:
316319
registry:
317-
image: registry:2
320+
image: registry:2.8.3@sha256:a3d8aaa63ed8681a604f1dea0aa03f100d5895b6a58ace528858a7b332415373
318321
ports:
319322
- 5000:5000
320323
steps:
321324
-
322325
name: Checkout
323-
uses: actions/checkout@v6
326+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
324327
-
325328
name: Set up Docker Buildx
326-
uses: docker/setup-buildx-action@v4
329+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
327330
with:
328331
version: ${{ env.BUILDX_VERSION }}
329332
driver-opts: network=host
@@ -345,7 +348,7 @@ jobs:
345348
type=sha
346349
-
347350
name: Build and push to local registry
348-
uses: docker/build-push-action@v7
351+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
349352
with:
350353
context: ./test
351354
file: ./test/Dockerfile
@@ -368,10 +371,10 @@ jobs:
368371
steps:
369372
-
370373
name: Checkout
371-
uses: actions/checkout@v6
374+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
372375
-
373376
name: Set up Docker Buildx
374-
uses: docker/setup-buildx-action@v4
377+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
375378
with:
376379
version: ${{ env.BUILDX_VERSION }}
377380
-
@@ -393,7 +396,7 @@ jobs:
393396
type=sha
394397
-
395398
name: Build
396-
uses: docker/bake-action@v7
399+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7.0.0
397400
with:
398401
files: |
399402
./test/docker-bake.hcl
@@ -413,10 +416,10 @@ jobs:
413416
steps:
414417
-
415418
name: Checkout
416-
uses: actions/checkout@v6
419+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
417420
-
418421
name: Set up Docker Buildx
419-
uses: docker/setup-buildx-action@v4
422+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
420423
with:
421424
version: ${{ env.BUILDX_VERSION }}
422425
driver: docker
@@ -431,7 +434,7 @@ jobs:
431434
sep-tags: ${{ matrix.sep }}
432435
-
433436
name: Tags
434-
uses: actions/github-script@v8
437+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
435438
with:
436439
script: |
437440
console.log(`${{ steps.meta.outputs.tags }}`);
@@ -441,10 +444,10 @@ jobs:
441444
steps:
442445
-
443446
name: Checkout
444-
uses: actions/checkout@v6
447+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
445448
-
446449
name: Set up Docker Buildx
447-
uses: docker/setup-buildx-action@v4
450+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
448451
with:
449452
version: ${{ env.BUILDX_VERSION }}
450453
driver: docker
@@ -462,7 +465,7 @@ jobs:
462465
maintainer=Foo
463466
-
464467
name: Build
465-
uses: docker/build-push-action@v7
468+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
466469
with:
467470
context: ./test
468471
file: ./test/output.Dockerfile
@@ -480,7 +483,7 @@ jobs:
480483
steps:
481484
-
482485
name: Checkout
483-
uses: actions/checkout@v6
486+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
484487
-
485488
name: Docker meta
486489
id: meta
@@ -504,10 +507,10 @@ jobs:
504507
steps:
505508
-
506509
name: Checkout
507-
uses: actions/checkout@v6
510+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
508511
-
509512
name: Set up Docker Buildx
510-
uses: docker/setup-buildx-action@v4
513+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
511514
with:
512515
version: ${{ env.BUILDX_VERSION }}
513516
-
@@ -531,7 +534,7 @@ jobs:
531534
DOCKER_METADATA_ANNOTATIONS_LEVELS: manifest,index
532535
-
533536
name: Build
534-
uses: docker/bake-action@v7
537+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7.0.0
535538
with:
536539
files: |
537540
./test/docker-bake.hcl
@@ -545,10 +548,10 @@ jobs:
545548
steps:
546549
-
547550
name: Checkout
548-
uses: actions/checkout@v6
551+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
549552
-
550553
name: Set up Docker Buildx
551-
uses: docker/setup-buildx-action@v4
554+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
552555
with:
553556
version: ${{ env.BUILDX_VERSION }}
554557
driver: docker
@@ -571,10 +574,10 @@ jobs:
571574
steps:
572575
-
573576
name: Checkout
574-
uses: actions/checkout@v6
577+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
575578
-
576579
name: Set up Docker Buildx
577-
uses: docker/setup-buildx-action@v4
580+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
578581
with:
579582
version: latest
580583
-
@@ -583,7 +586,7 @@ jobs:
583586
uses: ./
584587
-
585588
name: Build
586-
uses: docker/bake-action@v7
589+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7.0.0
587590
with:
588591
source: .
589592
files: |
@@ -604,10 +607,10 @@ jobs:
604607
steps:
605608
-
606609
name: Checkout
607-
uses: actions/checkout@v6
610+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
608611
-
609612
name: Set up Docker Buildx
610-
uses: docker/setup-buildx-action@v4
613+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
611614
with:
612615
version: ${{ env.BUILDX_VERSION }}
613616
driver: docker
@@ -628,7 +631,7 @@ jobs:
628631
steps:
629632
-
630633
name: Checkout
631-
uses: actions/checkout@v6
634+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
632635
-
633636
name: Dump context
634-
uses: crazy-max/ghaction-dump-context@v2
637+
uses: crazy-max/ghaction-dump-context@5355a8e5e6ac5a302e746a1c4b7747a0393863c8 # v2.3.0

.github/workflows/codeql.yml

Lines changed: 10 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,45 +1,46 @@
11
name: codeql
22

3+
permissions:
4+
contents: read
5+
36
on:
47
push:
58
branches:
69
- 'master'
710
- 'releases/v*'
811
pull_request:
912

10-
permissions:
11-
actions: read
12-
contents: read
13-
security-events: write
14-
1513
env:
1614
NODE_VERSION: "24"
1715

1816
jobs:
1917
analyze:
2018
runs-on: ubuntu-latest
19+
permissions:
20+
contents: read
21+
security-events: write
2122
steps:
2223
-
2324
name: Checkout
24-
uses: actions/checkout@v6
25+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2526
-
2627
name: Enable corepack
2728
run: |
2829
corepack enable
2930
yarn --version
3031
-
3132
name: Set up Node
32-
uses: actions/setup-node@v6
33+
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
3334
with:
3435
node-version: ${{ env.NODE_VERSION }}
3536
-
3637
name: Initialize CodeQL
37-
uses: github/codeql-action/init@v4
38+
uses: github/codeql-action/init@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1
3839
with:
3940
languages: javascript-typescript
4041
build-mode: none
4142
-
4243
name: Perform CodeQL Analysis
43-
uses: github/codeql-action/analyze@v4
44+
uses: github/codeql-action/analyze@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1
4445
with:
4546
category: "/language:javascript-typescript"

0 commit comments

Comments
 (0)