Skip to content

Commit d6df46f

Browse files
reberhardt7jdalton
authored andcommitted
fix: harden GitHub Actions workflows (zizmor)
- Add dependabot cooldown configuration (default 7 days) - Fix pnpm/action-setup SHA to match v5 tag (ref-version-mismatch) - Disable secrets-outside-env rule via .github/zizmor.yml
1 parent 3d14b95 commit d6df46f

3 files changed

Lines changed: 7 additions & 2 deletions

File tree

.github/dependabot.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,3 +8,5 @@ updates:
88
schedule:
99
interval: yearly
1010
open-pull-requests-limit: 0
11+
cooldown:
12+
default-days: 7

.github/workflows/weekly-update.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
cache: ''
3838

3939
- name: Setup pnpm
40-
uses: pnpm/action-setup@58e6119fe4f3092a76a7771efb55e04d25b6b26f # v5
40+
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
4141

4242
- name: Install dependencies
4343
shell: bash
@@ -77,7 +77,7 @@ jobs:
7777
cache: ''
7878

7979
- name: Setup pnpm
80-
uses: pnpm/action-setup@58e6119fe4f3092a76a7771efb55e04d25b6b26f # v5
80+
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
8181

8282
- name: Install dependencies
8383
shell: bash

.github/zizmor.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
rules:
2+
secrets-outside-env:
3+
disable: true

0 commit comments

Comments
 (0)