Skip to content

Commit 65f19a7

Browse files
authored
Merge pull request #875 from rgommers/ci-improvements
CI: improve security, add zizmor and trusted publishing
2 parents 2f98d2f + b967516 commit 65f19a7

6 files changed

Lines changed: 212 additions & 65 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,3 +11,5 @@ updates:
1111
- "*" # Group all Actions updates into a single larger pull request
1212
schedule:
1313
interval: monthly
14+
cooldown:
15+
default-days: 7

‎.github/workflows/emscripten.yml‎

Lines changed: 14 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,13 @@ on:
2323
# Run at 0300 hours on days 3 and 17 of the month
2424
- cron: "0 3 3,17 * *"
2525

26+
permissions:
27+
contents: read # to fetch code (actions/checkout)
28+
29+
concurrency:
30+
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
31+
cancel-in-progress: true
32+
2633
env:
2734
FORCE_COLOR: 3
2835

@@ -34,7 +41,9 @@ jobs:
3441
if: github.repository == 'PyWavelets/pywt'
3542
steps:
3643
- name: Check out repository
37-
uses: actions/checkout@v7.0.1
44+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
45+
with:
46+
persist-credentials: false
3847

3948
- name: Build and test PyWavelets
4049
uses: pypa/cibuildwheel@4726cd35bb13f7bde50cf2761f2499ac7b3aa32c # v4.1.1
@@ -47,11 +56,11 @@ jobs:
4756
# WARNING: this job will overwrite existing wheels.
4857
- name: Push wheels to Anaconda PyPI index
4958
if: >-
50-
(github.repository == 'PyWavelets/pywt') &&
51-
(github.event_name == 'push' && github.ref == 'refs/heads/main') ||
59+
github.repository == 'PyWavelets/pywt' &&
60+
((github.event_name == 'push' && github.ref == 'refs/heads/main') ||
5261
(github.event_name == 'workflow_dispatch' && github.event.inputs.push_wheels == 'true') ||
53-
(github.event_name == 'schedule')
54-
uses: scientific-python/upload-nightly-action@e76cfec8a4611fd02808a801b0ff5a7d7c1b2d99 # v0.6.4
62+
github.event_name == 'schedule')
63+
uses: scientific-python/upload-nightly-action@e76cfec8a4611fd02808a801b0ff5a7d7c1b2d99 # 0.6.4
5564
with:
5665
artifacts_path: wheelhouse/
5766
anaconda_nightly_upload_token: ${{ secrets.ANACONDA_ORG_UPLOAD_TOKEN }}

‎.github/workflows/lint.yml‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,9 @@ on:
99
- main
1010
- v1.**
1111

12+
permissions:
13+
contents: read # to fetch code (actions/checkout)
14+
1215
concurrency:
1316
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
1417
cancel-in-progress: true
@@ -21,10 +24,12 @@ jobs:
2124
python-version: ["3.13"]
2225

2326
steps:
24-
- uses: actions/checkout@v7.0.1
27+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
28+
with:
29+
persist-credentials: false
2530

2631
- name: Set up Python ${{ matrix.python-version }}
27-
uses: actions/setup-python@v7
32+
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
2833
with:
2934
python-version: ${{ matrix.python-version }}
3035

‎.github/workflows/tests.yml‎

Lines changed: 17 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,11 @@ on:
99
- main
1010
- v1.**
1111

12+
permissions:
13+
contents: read # to fetch code (actions/checkout)
14+
1215
concurrency:
13-
# avoid duplicate runs on both pushes and PRs
14-
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
16+
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
1517
cancel-in-progress: true
1618

1719
env:
@@ -70,8 +72,10 @@ jobs:
7072
python-version: "3.14"
7173
OPTIONS_NAME: "editable-install"
7274
steps:
73-
- uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v4.1.2
74-
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v5.5.0
75+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
76+
with:
77+
persist-credentials: false
78+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
7579
with:
7680
python-version: ${{ matrix.python-version}}
7781
allow-prereleases: true
@@ -160,8 +164,10 @@ jobs:
160164
matrix:
161165
python-version: ["3.14t", "3.15t-dev"]
162166
steps:
163-
- uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v4.1.2
164-
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v5.5.0
167+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
168+
with:
169+
persist-credentials: false
170+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
165171
with:
166172
python-version: ${{ matrix.python-version}}
167173

@@ -199,8 +205,10 @@ jobs:
199205
OPTIONS_NAME: "pre-releases"
200206

201207
steps:
202-
- uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v4.1.2
203-
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v5.5.0
208+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
209+
with:
210+
persist-credentials: false
211+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
204212
with:
205213
python-version: ${{ matrix.python-version}}
206214
allow-prereleases: true
@@ -281,7 +289,7 @@ jobs:
281289
# the test run itself is configured in the "Test" step below.
282290
ASAN_OPTIONS: detect_leaks=0
283291
steps:
284-
- uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v4.2.2
292+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
285293
with:
286294
submodules: recursive
287295
fetch-tags: true

0 commit comments

Comments
 (0)