File tree Expand file tree Collapse file tree 2 files changed +8
-7
lines changed
Expand file tree Collapse file tree 2 files changed +8
-7
lines changed Original file line number Diff line number Diff line change @@ -244,6 +244,6 @@ jobs:
244244 merge-multiple : true
245245
246246 - name : Publish distributions
247- uses : pypa/gh-action-pypi-publish@15c56dba361d8335944d31a2ecd17d700fc7bcbc # release/v1
247+ uses : pypa/gh-action-pypi-publish@67339c736fd9354cd4f8cb0b744f2b82a74b5c70 # v1.12.3
248248 with :
249249 attestations : true
Original file line number Diff line number Diff line change 88
99jobs :
1010 zizmor :
11- name : zizmor latest via Cargo
11+ name : zizmor latest via PyPI
1212 runs-on : ubuntu-latest
1313 permissions :
1414 security-events : write
@@ -20,14 +20,15 @@ jobs:
2020 uses : actions/checkout@v4
2121 with :
2222 persist-credentials : false
23- - name : Setup Rust
24- uses : actions-rust-lang/setup-rust-toolchain@v1
25- - name : Get zizmor
26- run : cargo install zizmor
23+
24+ - name : Install the latest version of uv
25+ uses : astral-sh/setup-uv@v4
26+
2727 - name : Run zizmor 🌈
28- run : zizmor --format sarif . > results.sarif
28+ run : uvx zizmor --format sarif . > results.sarif
2929 env :
3030 GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
31+
3132 - name : Upload SARIF file
3233 uses : github/codeql-action/upload-sarif@v3
3334 with :
You can’t perform that action at this time.
0 commit comments