diff --git a/.github/workflows/label-check.yaml b/.github/workflows/label-check.yaml index 5c4aee6..4fce29c 100644 --- a/.github/workflows/label-check.yaml +++ b/.github/workflows/label-check.yaml @@ -9,6 +9,8 @@ on: - unlabeled - synchronize +permissions: {} + env: LABELS: ${{ join( github.event.pull_request.labels.*.name, ' ' ) }} diff --git a/.github/workflows/milestone-merged-prs.yaml b/.github/workflows/milestone-merged-prs.yaml index f455839..f98629d 100644 --- a/.github/workflows/milestone-merged-prs.yaml +++ b/.github/workflows/milestone-merged-prs.yaml @@ -1,12 +1,14 @@ name: Milestone on: - pull_request_target: + pull_request_target: # zizmor: ignore[dangerous-triggers] types: - closed branches: - "main" +permissions: {} + jobs: milestone_pr: name: attach to PR diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 73564b6..6d0f5b9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -14,11 +14,12 @@ jobs: # IMPORTANT: this permission is mandatory for trusted publishing id-token: write steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - - uses: actions/setup-python@v6 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 name: Install Python with: python-version: "3.11" @@ -30,4 +31,4 @@ jobs: python -m build --sdist --wheel - name: Publish package distributions to PyPI - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 1e50c57..6bb78a7 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -24,8 +24,10 @@ jobs: os: [ubuntu-latest, windows-latest, macos-latest] runs-on: ${{ matrix.os }} steps: - - uses: actions/checkout@v5 - - uses: actions/setup-python@v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 id: setup-python with: python-version: ${{ matrix.python_version }} diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 20bc253..253982d 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -25,14 +25,14 @@ repos: - id: trailing-whitespace - repo: https://github.com/rbubley/mirrors-prettier - rev: 14abee445aea04b39069c19b4bd54efff6775819 # frozen: v3.7.4 + rev: ef4a397f916211b4a39ccf9d3d9cbb6562157251 # frozen: v3.9.9 hooks: - id: prettier files: \.(css|html|md|yml|yaml|toml) args: [--prose-wrap=preserve] - repo: https://github.com/astral-sh/ruff-pre-commit - rev: 5ba58aca0bd5bc7c0e1c0fc45af2e88d6a2bde83 # frozen: v0.14.10 + rev: f12be1ebaa5351c1fc76472de98db2c3446c8253 # frozen: v0.16.10 hooks: - id: ruff args: ["--fix", "--show-fixes", "--exit-non-zero-on-fix"] @@ -44,7 +44,7 @@ repos: - id: blacken-docs - repo: https://github.com/pre-commit/mirrors-mypy - rev: a66e98df7b4aeeb3724184b332785976d062b92e # frozen: v1.19.1 + rev: 2834ec6639549dd6796205c8f011dedcd587288b # frozen: v2.4.0 hooks: - id: mypy exclude: | @@ -52,8 +52,15 @@ repos: ^example_pkg_src/ ) + - repo: https://github.com/zizmorcore/zizmor-pre-commit + rev: fa412071e4f5d44d44f9e365f4676f9df92456a2 # frozen: v1.30.1 + hooks: + # Run the linter. + - id: zizmor + args: [--no-progress, --fix] + - repo: https://github.com/codespell-project/codespell - rev: "63c8f8312b7559622c0d82815639671ae42132ac" # frozen: v2.4.1 + rev: "57b21406f092110c18776e39b0bda50d37c945c8" # frozen: v2.4.3 hooks: - id: codespell args: ["-L", "ans"] diff --git a/pyproject.toml b/pyproject.toml index 8a04ba0..937aa46 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -27,7 +27,7 @@ classifiers = [ "Programming Language :: Python :: 3 :: Only", ] dependencies = [ - "click>=8,!=8.3.0,<8.4", + "click>=8,!=8.3.0,<8.5", "tomli; python_version < '3.11'", "colorama; platform_system == 'Windows'", "importlib_metadata >= 7" @@ -38,7 +38,7 @@ dynamic = ['version'] spin = "spin.__main__:main" [project.optional-dependencies] -lint = ["pre-commit == 4.3.0"] +lint = ["pre-commit == 4.6.0"] dev = ["changelist == 0.5"] [project.urls]