Skip to content

Commit c1e7488

Browse files
committed
ci: Checkout after downloading files to prevent poisioning
Signed-off-by: Philippe Coval <[email protected]>
1 parent 6dfd644 commit c1e7488

File tree

1 file changed

+6
-5
lines changed

1 file changed

+6
-5
lines changed

.github/workflows/test.yml

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -46,11 +46,6 @@ jobs:
4646
rm -rfv "${file}"
4747
echo "TODO: https://docs.docker.com/engine/security/trust/"
4848
# yamllint enable rule:line-length
49-
# yamllint disable-line rule:line-length
50-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
51-
with:
52-
fetch-depth: 0
53-
ref: ${{ github.event.workflow_run.head_commit.id }}
5449

5550
- name: Download embedded applications package
5651
# yamllint disable-line rule:line-length
@@ -78,6 +73,12 @@ jobs:
7873
&& rm z-wave-stack-binaries-*-Linux.tar.gz
7974
&& date -u
8075
76+
# yamllint disable-line rule:line-length
77+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
78+
with:
79+
fetch-depth: 0
80+
ref: ${{ github.event.workflow_run.head_commit.id }}
81+
8182
- name: Run
8283
id: run
8384
# yamllint disable rule:line-length

0 commit comments

Comments
 (0)