Skip to content

Commit 20c128a

Browse files
authored
Merge pull request #6975 from dcampbell24/zizmor-fix-01
Set persist-credentials: false
2 parents 0e11bbf + 655defd commit 20c128a

File tree

8 files changed

+54
-0
lines changed

8 files changed

+54
-0
lines changed

.github/workflows/CICD.yml

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,8 @@ jobs:
3737
runs-on: ubuntu-latest
3838
steps:
3939
- uses: actions/checkout@v4
40+
with:
41+
persist-credentials: false
4042
- uses: EmbarkStudios/cargo-deny-action@v2
4143

4244
style_deps:
@@ -54,6 +56,8 @@ jobs:
5456
- { os: windows-latest , features: feat_os_windows }
5557
steps:
5658
- uses: actions/checkout@v4
59+
with:
60+
persist-credentials: false
5761
- uses: dtolnay/rust-toolchain@nightly
5862
## note: requires 'nightly' toolchain b/c `cargo-udeps` uses the `rustc` '-Z save-analysis' option
5963
## * ... ref: <https://github.com/est31/cargo-udeps/issues/73>
@@ -106,6 +110,8 @@ jobs:
106110
# - { os: windows-latest , features: feat_os_windows }
107111
steps:
108112
- uses: actions/checkout@v4
113+
with:
114+
persist-credentials: false
109115
- uses: dtolnay/rust-toolchain@master
110116
with:
111117
toolchain: stable
@@ -159,6 +165,8 @@ jobs:
159165
- { os: ubuntu-latest , features: feat_os_unix }
160166
steps:
161167
- uses: actions/checkout@v4
168+
with:
169+
persist-credentials: false
162170
- uses: dtolnay/rust-toolchain@master
163171
with:
164172
toolchain: ${{ env.RUST_MIN_SRV }}
@@ -227,6 +235,8 @@ jobs:
227235
- { os: ubuntu-latest , features: feat_os_unix }
228236
steps:
229237
- uses: actions/checkout@v4
238+
with:
239+
persist-credentials: false
230240
- uses: dtolnay/rust-toolchain@stable
231241
- uses: Swatinem/rust-cache@v2
232242
- name: "`cargo update` testing"
@@ -250,6 +260,8 @@ jobs:
250260
- { os: ubuntu-latest , features: feat_os_unix }
251261
steps:
252262
- uses: actions/checkout@v4
263+
with:
264+
persist-credentials: false
253265
- uses: dtolnay/rust-toolchain@stable
254266
- uses: taiki-e/install-action@nextest
255267
- uses: Swatinem/rust-cache@v2
@@ -304,6 +316,8 @@ jobs:
304316
- { os: windows-latest , features: feat_os_windows }
305317
steps:
306318
- uses: actions/checkout@v4
319+
with:
320+
persist-credentials: false
307321
- uses: dtolnay/rust-toolchain@stable
308322
- uses: taiki-e/install-action@nextest
309323
- uses: Swatinem/rust-cache@v2
@@ -331,6 +345,8 @@ jobs:
331345
- { os: windows-latest , features: feat_os_windows }
332346
steps:
333347
- uses: actions/checkout@v4
348+
with:
349+
persist-credentials: false
334350
- uses: dtolnay/rust-toolchain@nightly
335351
- uses: taiki-e/install-action@nextest
336352
- uses: Swatinem/rust-cache@v2
@@ -355,6 +371,8 @@ jobs:
355371
- { os: ubuntu-latest , features: feat_os_unix }
356372
steps:
357373
- uses: actions/checkout@v4
374+
with:
375+
persist-credentials: false
358376
- uses: dtolnay/rust-toolchain@stable
359377
- uses: Swatinem/rust-cache@v2
360378
- name: Run sccache-cache
@@ -485,6 +503,8 @@ jobs:
485503
- { os: windows-latest , target: aarch64-pc-windows-msvc , features: feat_os_windows, use-cross: use-cross , skip-tests: true }
486504
steps:
487505
- uses: actions/checkout@v4
506+
with:
507+
persist-credentials: false
488508
- uses: dtolnay/rust-toolchain@master
489509
with:
490510
toolchain: ${{ env.RUST_MIN_SRV }}
@@ -780,6 +800,8 @@ jobs:
780800
## VARs setup
781801
echo "TEST_SUMMARY_FILE=busybox-result.json" >> $GITHUB_OUTPUT
782802
- uses: actions/checkout@v4
803+
with:
804+
persist-credentials: false
783805
- uses: Swatinem/rust-cache@v2
784806
- name: Run sccache-cache
785807
uses: mozilla-actions/sccache-action@v0.0.7
@@ -860,6 +882,8 @@ jobs:
860882
TEST_SUMMARY_FILE="toybox-result.json"
861883
outputs TEST_SUMMARY_FILE
862884
- uses: actions/checkout@v4
885+
with:
886+
persist-credentials: false
863887
- uses: dtolnay/rust-toolchain@master
864888
with:
865889
toolchain: ${{ env.RUST_MIN_SRV }}
@@ -935,6 +959,8 @@ jobs:
935959
os: [ubuntu-latest, macos-latest, windows-latest]
936960
steps:
937961
- uses: actions/checkout@v4
962+
with:
963+
persist-credentials: false
938964
- uses: dtolnay/rust-toolchain@stable
939965
- uses: Swatinem/rust-cache@v2
940966
- name: build and test all programs individually

.github/workflows/CheckScripts.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,8 @@ jobs:
3030
contents: read
3131
steps:
3232
- uses: actions/checkout@v4
33+
with:
34+
persist-credentials: false
3335
- name: Run ShellCheck
3436
uses: ludeeus/action-shellcheck@master
3537
env:
@@ -46,6 +48,8 @@ jobs:
4648
contents: read
4749
steps:
4850
- uses: actions/checkout@v4
51+
with:
52+
persist-credentials: false
4953
- name: Setup shfmt
5054
uses: mfinelli/setup-shfmt@v3
5155
- name: Run shfmt

.github/workflows/FixPR.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,8 @@ jobs:
2727
- { os: ubuntu-latest , features: feat_os_unix }
2828
steps:
2929
- uses: actions/checkout@v4
30+
with:
31+
persist-credentials: false
3032
- name: Initialize job variables
3133
id: vars
3234
shell: bash
@@ -86,6 +88,8 @@ jobs:
8688
- { os: ubuntu-latest , features: feat_os_unix }
8789
steps:
8890
- uses: actions/checkout@v4
91+
with:
92+
persist-credentials: false
8993
- name: Initialize job variables
9094
id: vars
9195
shell: bash

.github/workflows/GnuTests.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,7 @@ jobs:
6565
uses: actions/checkout@v4
6666
with:
6767
path: '${{ steps.vars.outputs.path_UUTILS }}'
68+
persist-credentials: false
6869
- uses: dtolnay/rust-toolchain@master
6970
with:
7071
toolchain: stable
@@ -79,6 +80,7 @@ jobs:
7980
path: '${{ steps.vars.outputs.path_GNU }}'
8081
ref: ${{ steps.vars.outputs.repo_GNU_ref }}
8182
submodules: false
83+
persist-credentials: false
8284

8385
- name: Override submodule URL and initialize submodules
8486
# Use github instead of upstream git server

.github/workflows/android.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,8 @@ jobs:
7979
sudo udevadm control --reload-rules
8080
sudo udevadm trigger --name-match=kvm
8181
- uses: actions/checkout@v4
82+
with:
83+
persist-credentials: false
8284
- name: Collect information about runner
8385
if: always()
8486
continue-on-error: true

.github/workflows/code-quality.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,8 @@ jobs:
3232
- { os: ubuntu-latest , features: feat_os_unix }
3333
steps:
3434
- uses: actions/checkout@v4
35+
with:
36+
persist-credentials: false
3537
- uses: dtolnay/rust-toolchain@master
3638
with:
3739
toolchain: stable
@@ -75,6 +77,8 @@ jobs:
7577
- { os: windows-latest , features: feat_os_windows }
7678
steps:
7779
- uses: actions/checkout@v4
80+
with:
81+
persist-credentials: false
7882
- uses: dtolnay/rust-toolchain@master
7983
with:
8084
toolchain: stable
@@ -120,6 +124,8 @@ jobs:
120124
- { os: ubuntu-latest , features: feat_os_unix }
121125
steps:
122126
- uses: actions/checkout@v4
127+
with:
128+
persist-credentials: false
123129
- name: Initialize workflow variables
124130
id: vars
125131
shell: bash
@@ -156,6 +162,8 @@ jobs:
156162
steps:
157163
- name: Clone repository
158164
uses: actions/checkout@v4
165+
with:
166+
persist-credentials: false
159167

160168
- name: Check
161169
run: npx --yes @taplo/cli fmt --check

.github/workflows/freebsd.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,8 @@ jobs:
3535
RUSTC_WRAPPER: "sccache"
3636
steps:
3737
- uses: actions/checkout@v4
38+
with:
39+
persist-credentials: false
3840
- uses: Swatinem/rust-cache@v2
3941
- name: Run sccache-cache
4042
uses: mozilla-actions/sccache-action@v0.0.7
@@ -127,6 +129,8 @@ jobs:
127129
RUSTC_WRAPPER: "sccache"
128130
steps:
129131
- uses: actions/checkout@v4
132+
with:
133+
persist-credentials: false
130134
- uses: Swatinem/rust-cache@v2
131135
- name: Run sccache-cache
132136
uses: mozilla-actions/sccache-action@v0.0.7

.github/workflows/fuzzing.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@ jobs:
2222
runs-on: ubuntu-latest
2323
steps:
2424
- uses: actions/checkout@v4
25+
with:
26+
persist-credentials: false
2527
- uses: dtolnay/rust-toolchain@nightly
2628
- name: Install `cargo-fuzz`
2729
run: cargo install cargo-fuzz
@@ -62,6 +64,8 @@ jobs:
6264

6365
steps:
6466
- uses: actions/checkout@v4
67+
with:
68+
persist-credentials: false
6569
- uses: dtolnay/rust-toolchain@nightly
6670
- name: Install `cargo-fuzz`
6771
run: cargo install cargo-fuzz

0 commit comments

Comments
 (0)