Skip to content

Commit b8e7a6c

Browse files
authored
deps: bump pypi-publish (#83)
1 parent b5aa11f commit b8e7a6c

File tree

2 files changed

+8
-7
lines changed

2 files changed

+8
-7
lines changed

.github/workflows/CI.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -244,6 +244,6 @@ jobs:
244244
merge-multiple: true
245245

246246
- name: Publish distributions
247-
uses: pypa/gh-action-pypi-publish@15c56dba361d8335944d31a2ecd17d700fc7bcbc # release/v1
247+
uses: pypa/gh-action-pypi-publish@67339c736fd9354cd4f8cb0b744f2b82a74b5c70 # v1.12.3
248248
with:
249249
attestations: true

.github/workflows/zizmor.yml

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ on:
88

99
jobs:
1010
zizmor:
11-
name: zizmor latest via Cargo
11+
name: zizmor latest via PyPI
1212
runs-on: ubuntu-latest
1313
permissions:
1414
security-events: write
@@ -20,14 +20,15 @@ jobs:
2020
uses: actions/checkout@v4
2121
with:
2222
persist-credentials: false
23-
- name: Setup Rust
24-
uses: actions-rust-lang/setup-rust-toolchain@v1
25-
- name: Get zizmor
26-
run: cargo install zizmor
23+
24+
- name: Install the latest version of uv
25+
uses: astral-sh/setup-uv@v4
26+
2727
- name: Run zizmor 🌈
28-
run: zizmor --format sarif . > results.sarif
28+
run: uvx zizmor --format sarif . > results.sarif
2929
env:
3030
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
31+
3132
- name: Upload SARIF file
3233
uses: github/codeql-action/upload-sarif@v3
3334
with:

0 commit comments

Comments
 (0)