Skip to content

Commit df02e82

Browse files
committed
fix it
1 parent 720975a commit df02e82

2 files changed

Lines changed: 8 additions & 26 deletions

File tree

.github/workflows/sync_copilot.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,12 +28,14 @@ jobs:
2828
with:
2929
ref: ${{ inputs.calling_repo_base_branch }}
3030
fetch-depth: 0
31+
persist-credentials: false
3132

3233
- name: Checkout central repo code
3334
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
3435
with:
3536
ref: ${{ inputs.common_workflows_ref }}
3637
fetch-depth: 0
38+
persist-credentials: false
3739
path: eps-common-workflows
3840
repository: NHSDigital/eps-common-workflows
3941
sparse-checkout: |

zizmor.yml

Lines changed: 6 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -5,35 +5,15 @@ rules:
55
secrets-outside-env:
66
ignore:
77
# these workflows use secrets outside of an environment because it is passed into the workflow
8-
- tag-release-devcontainer.yml:108:39
9-
- tag-release-devcontainer.yml:228:34
10-
- tag-release-devcontainer.yml:234:35
11-
- tag-release-devcontainer.yml:240:34
12-
- tag-release-devcontainer.yml:248:35
13-
- update-dev-container-version.yml:135:24
14-
- update-dev-container-version.yml:136:29
15-
- quality-checks-devcontainer.yml:211:28
16-
- quality-checks-devcontainer.yml:204:28
17-
- quality-checks-devcontainer.yml:191:29
18-
- dependabot-auto-approve-and-merge.yml:24:31
19-
- dependabot-auto-approve-and-merge.yml:25:36
20-
- tag-release-devcontainer.yml:230:34
21-
- tag-release-devcontainer.yml:236:35
22-
- tag-release-devcontainer.yml:242:34
23-
- tag-release-devcontainer.yml:250:35
24-
- update-dev-container-version.yml:136:24
25-
- update-dev-container-version.yml:137:29
26-
- update-dev-container-version.yml:133:24
27-
- update-dev-container-version.yml:134:29
8+
- tag-release-devcontainer.yml
9+
- update-dev-container-version.yml
10+
- quality-checks-devcontainer.yml
11+
- dependabot-auto-approve-and-merge.yml
2812
unpinned-images:
2913
# these workflows use unpinned images because they are using a full image passed in that contains the tag
3014
ignore:
31-
- quality-checks-devcontainer.yml:32:7
32-
- quality-checks-devcontainer.yml:216:7
33-
- quality-checks-devcontainer.yml:286:7
34-
- quality-checks-devcontainer.yml:329:7
35-
- tag-release-devcontainer.yml:89:13
36-
- quality-checks-devcontainer.yml:331:7
15+
- quality-checks-devcontainer.yml
16+
- tag-release-devcontainer.yml
3717
excessive-permissions:
3818
# these are possible excessive permissions but need time to work out if they are actually excessive or not
3919
ignore:

0 commit comments

Comments
 (0)