diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8734252..5d09f30 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,6 +13,8 @@ concurrency: ${{ github.event.pull_request.number || github.sha }} cancel-in-progress: true +permissions: {} + jobs: tests: name: tests / ${{ matrix.os }} / ${{ matrix.python-version }} @@ -28,10 +30,12 @@ jobs: python-version: pypy3.10 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false # Get Python to test against - - uses: actions/setup-python@v5 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: ${{ matrix.python-version }} allow-prereleases: true @@ -42,10 +46,13 @@ jobs: # prettier-ignore - run: > nox - -s test-${{ matrix.python-version }} - doctest-${{ matrix.python-version }} + -s test-${PYTHON_VERSION} + doctest-${PYTHON_VERSION} --error-on-missing-interpreters if: matrix.python-version != 'pypy3.10' + shell: bash + env: + PYTHON_VERSION: ${{ matrix.python-version }} - run: nox --error-on-missing-interpreters -s test-pypy3 doctest-pypy3 if: matrix.python-version == 'pypy3.10' diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index ba75968..8cc3126 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -6,18 +6,25 @@ on: permissions: {} +concurrency: + group: >- + ${{ github.workflow }}- + ${{ github.ref_type }}- + ${{ github.event.pull_request.number || github.sha }} + cancel-in-porgress: true + jobs: build: name: Build runs-on: ubuntu-latest steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - run: pipx run build - - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: distfiles path: dist/ @@ -30,14 +37,14 @@ jobs: name: release url: https://pypi.org/project/installer/ permissions: - id-token: write + id-token: write # trusted publishing + attestations needs: build steps: - - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: distfiles path: dist/ - - uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # v1.13.0 + - uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 with: print-hash: true diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 79436b9..87609ac 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -30,3 +30,9 @@ repos: hooks: - id: ruff-check - id: ruff-format + + - repo: https://github.com/zizmorcore/zizmor-pre-commit + rev: v1.30.1 + hooks: + - id: zizmor + args: ["--pedantic"]