Skip to content

Commit 4e343ca

Browse files
committed
use zizmor
1 parent f2d4d69 commit 4e343ca

7 files changed

Lines changed: 29 additions & 197 deletions

File tree

.devcontainer/devcontainer.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"args": {
77
"DOCKER_GID": "${env:DOCKER_GID:}",
88
"IMAGE_NAME": "node_24_python_3_14",
9-
"IMAGE_VERSION": "v1.2.0",
9+
"IMAGE_VERSION": "pr-68-7f136dd",
1010
"USER_UID": "${localEnv:USER_ID:}",
1111
"USER_GID": "${localEnv:GROUP_ID:}"
1212
},

.github/workflows/combine-dependabot-prs.yml

Lines changed: 0 additions & 67 deletions
This file was deleted.

.github/workflows/dependabot-auto-approve-and-merge.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ permissions:
1515
jobs:
1616
dependabot:
1717
runs-on: ubuntu-22.04
18-
if: ${{ github.actor == 'dependabot[bot]' }}
18+
if: (github.event.pull_request.user.login == 'dependabot[bot]' || github.event.pull_request.user.login == 'eps-create-pull-request[bot]') && github.repository == github.event.pull_request.head.repo.full_name
1919
steps:
2020
- name: Get token from Github App
2121
id: get_app_token

.github/workflows/get-repo-config.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,7 @@ jobs:
5353
with:
5454
ref: ${{ env.BRANCH_NAME }}
5555
fetch-depth: 0
56+
persist-credentials: false
5657

5758
- name: Load config value
5859
id: load-config

.github/workflows/pull_request.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,4 +43,3 @@ jobs:
4343
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
4444
branch_name: ${{ github.event.pull_request.head.ref }}
4545
tag_format: ${{ needs.get_config_values.outputs.tag_format }}
46-
secrets: inherit

combine-prs.js

Lines changed: 0 additions & 127 deletions
This file was deleted.

zizmor.yml

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
rules:
2+
dependabot-cooldown:
3+
config:
4+
days: 3
5+
secrets-outside-env:
6+
ignore:
7+
# this workflow uses secrets outside of an environment
8+
- tag-release-devcontainer.yml:108:39
9+
- tag-release-devcontainer.yml:228:34
10+
- tag-release-devcontainer.yml:234:35
11+
- tag-release-devcontainer.yml:240:34
12+
- tag-release-devcontainer.yml:248:35
13+
- update-dev-container-version.yml:135:24
14+
- update-dev-container-version.yml:136:29
15+
- quality-checks-devcontainer.yml:210:28
16+
- quality-checks-devcontainer.yml:203:28
17+
- quality-checks-devcontainer.yml:190:29
18+
- dependabot-auto-approve-and-merge.yml:24:31
19+
- dependabot-auto-approve-and-merge.yml:25:36
20+
unpinned-images:
21+
ignore:
22+
- quality-checks-devcontainer.yml:32:7
23+
- quality-checks-devcontainer.yml:215:7
24+
- quality-checks-devcontainer.yml:285:7
25+
- quality-checks-devcontainer.yml:328:7
26+
- tag-release-devcontainer.yml:89:13

0 commit comments

Comments
 (0)