Skip to content

Commit 22c27f8

Browse files
committed
ci: Resolve audit issues reported by zizmore
Resolve two cases of `ref-version-mismatch` and various `artipacked` instances.
1 parent 3d14fe4 commit 22c27f8

2 files changed

Lines changed: 16 additions & 7 deletions

File tree

.github/workflows/main.yaml

Lines changed: 15 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,7 @@ jobs:
3131
steps:
3232
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
3333
with:
34+
persist-credentials: false
3435
fetch-depth: 500
3536
- name: Fetch pull request ref
3637
run: git fetch origin "$GITHUB_REF:$GITHUB_REF"
@@ -125,6 +126,7 @@ jobs:
125126
run: sudo apt-get update && sudo apt-get install -y rustup
126127

127128
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
129+
with: { persist-credentials: false }
128130
- name: Install Rust (rustup)
129131
shell: bash
130132
run: |
@@ -135,7 +137,7 @@ jobs:
135137
rustup default "$channel"
136138
rustup target add "$JOB_TARGET"
137139
138-
- uses: taiki-e/install-action@de6bbd1333b8f331563d54a051e542c7dfef81c3 # v2
140+
- uses: taiki-e/install-action@de6bbd1333b8f331563d54a051e542c7dfef81c3 # v2.68.34
139141
with:
140142
tool: nextest@0.9.130
141143

@@ -205,6 +207,7 @@ jobs:
205207
timeout-minutes: 10
206208
steps:
207209
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
210+
with: { persist-credentials: false }
208211
# Unlike rustfmt, stable clippy does not work on code with nightly features.
209212
- name: Install nightly `clippy`
210213
run: |
@@ -223,18 +226,17 @@ jobs:
223226
security-events: write
224227
timeout-minutes: 10
225228
steps:
226-
- name: Checkout repository
227-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
228-
229-
- name: Run zizmor
230-
uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2
229+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
230+
with: { persist-credentials: false }
231+
- uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2
231232

232233
build-custom:
233234
name: Build custom target
234235
runs-on: ubuntu-24.04
235236
timeout-minutes: 10
236237
steps:
237238
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
239+
with: { persist-credentials: false }
238240
- name: Install Rust
239241
run: |
240242
rustup update nightly --no-self-update
@@ -256,6 +258,7 @@ jobs:
256258
timeout-minutes: 10
257259
steps:
258260
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
261+
with: { persist-credentials: false }
259262
- name: Install Rust
260263
run: |
261264
rustup update nightly --no-self-update
@@ -284,7 +287,8 @@ jobs:
284287
JOB_TARGET: ${{ matrix.target }}
285288
steps:
286289
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
287-
- uses: taiki-e/install-action@de6bbd1333b8f331563d54a051e542c7dfef81c3 # v2
290+
with: { persist-credentials: false }
291+
- uses: taiki-e/install-action@de6bbd1333b8f331563d54a051e542c7dfef81c3 # v2.68.34
288292
with:
289293
tool: cargo-binstall@1.17.7
290294

@@ -322,6 +326,7 @@ jobs:
322326
timeout-minutes: 10
323327
steps:
324328
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
329+
with: { persist-credentials: false }
325330
- name: Install Rust (rustup)
326331
run: rustup update nightly --no-self-update && rustup default nightly
327332
shell: bash
@@ -338,6 +343,7 @@ jobs:
338343
RUSTFLAGS: # No need to check warnings on old MSRV, unset `-Dwarnings`
339344
steps:
340345
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
346+
with: { persist-credentials: false }
341347
- name: Install Rust
342348
run: |
343349
msrv="$(perl -ne 'print if s/rust-version\s*=\s*"(.*)"/\1/g' libm/Cargo.toml)"
@@ -356,6 +362,7 @@ jobs:
356362
timeout-minutes: 10
357363
steps:
358364
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
365+
with: { persist-credentials: false }
359366
- name: Install nightly `rustfmt`
360367
run: rustup set profile minimal && rustup default nightly && rustup component add rustfmt
361368
- run: cargo fmt -- --check
@@ -379,6 +386,7 @@ jobs:
379386
TO_TEST: ${{ matrix.to_test }}
380387
steps:
381388
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
389+
with: { persist-credentials: false }
382390
- name: Install Rust
383391
run: |
384392
rustup update nightly --no-self-update

.github/workflows/publish.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ jobs:
1515
steps:
1616
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
1717
with:
18+
persist-credentials: false
1819
fetch-depth: 0
1920
- name: Install Rust (rustup)
2021
run: rustup update nightly --no-self-update && rustup default nightly

0 commit comments

Comments
 (0)