Skip to content

Commit 6590f96

Browse files
authored
Harden permissions and pin versions in CI workflow
Updated contents to match `expressive-code` main repo.
1 parent 42d2f13 commit 6590f96

File tree

1 file changed

+8
-5
lines changed

1 file changed

+8
-5
lines changed

.github/workflows/ci.yml

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
name: CI
2+
permissions: {}
23

34
on:
45
push:
@@ -13,15 +14,17 @@ jobs:
1314
runs-on: ubuntu-latest
1415
steps:
1516
- name: Check out repository
16-
uses: actions/checkout@v4
17-
17+
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
18+
with:
19+
persist-credentials: false
20+
1821
- name: Setup PNPM
19-
uses: pnpm/action-setup@v4
22+
uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
2023

2124
- name: Setup Node.js
22-
uses: actions/setup-node@v4
25+
uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
2326
with:
24-
node-version: 20
27+
node-version: 24
2528
cache: 'pnpm'
2629

2730
- name: Install dependencies

0 commit comments

Comments
 (0)