Skip to content

ci: fix YAML nits, use zizmor to pin dependencies#1691

Open
tob-scott-a wants to merge 1 commit intoRustCrypto:masterfrom
tob-scott-a:ci-update
Open

ci: fix YAML nits, use zizmor to pin dependencies#1691
tob-scott-a wants to merge 1 commit intoRustCrypto:masterfrom
tob-scott-a:ci-update

Conversation

@tob-scott-a
Copy link
Copy Markdown

No description provided.

@tarcieri
Copy link
Copy Markdown
Member

Outside the special "publish" environment/workflow, we only allow Actions read-only access.

Therefore outside that special environment, I'm not sure how helpful it actually is to pin dependencies used by Actions itself. It leads to a lot of Dependabot spam when they're updated, and I'm not sure any of the threats that would be mitigated in a such a read-only CI environment are particularly concerning.

(If there are ways to perform non-read-only requests from Actions, that's a separate issue that's worth mitigating)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants