Skip to content

Commit

Permalink
Do not persist credentials on GH Actions
Browse files Browse the repository at this point in the history
I ran a GH Actions safety checker, which suggested that the
"persist-credentials" option should be set to "false".
The rationale: https://woodruffw.github.io/zizmor/audits/#artipacked. It is not
a big issue for us, as we don't upload artifacts from GH Actions, but using
this option should add a bit of safety anyway.
  • Loading branch information
gustawlippa committed Dec 12, 2024
1 parent 91cdfa1 commit 7241910
Showing 1 changed file with 7 additions and 0 deletions.
7 changes: 7 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ jobs:
- uses: actions/checkout@v3
with:
fetch-depth: 0
persist-credentials: false
- uses: erlef/[email protected]
with:
otp-version: ${{ matrix.otp }}
Expand Down Expand Up @@ -82,6 +83,7 @@ jobs:
- uses: actions/checkout@v3
with:
fetch-depth: 0
persist-credentials: false
- uses: ./.github/actions/big-tests
with:
otp: ${{matrix.otp}}
Expand Down Expand Up @@ -112,6 +114,7 @@ jobs:
- uses: actions/checkout@v3
with:
fetch-depth: 0
persist-credentials: false
- uses: ./.github/actions/big-tests
with:
otp: ${{matrix.otp}}
Expand Down Expand Up @@ -146,6 +149,7 @@ jobs:
- uses: actions/checkout@v3
with:
fetch-depth: 0
persist-credentials: false
- uses: erlef/[email protected]
with:
otp-version: ${{matrix.otp}}
Expand All @@ -162,6 +166,7 @@ jobs:
- uses: actions/checkout@v3
with:
fetch-depth: 0
persist-credentials: false
- uses: erlef/[email protected]
with:
otp-version: ${{matrix.otp}}
Expand All @@ -178,6 +183,7 @@ jobs:
- uses: actions/checkout@v3
with:
fetch-depth: 0
persist-credentials: false
- uses: erlef/[email protected]
with:
otp-version: ${{matrix.otp}}
Expand All @@ -200,4 +206,5 @@ jobs:
- uses: actions/checkout@v3
with:
fetch-depth: 0
persist-credentials: false
- run: tools/test.sh -p pkg

0 comments on commit 7241910

Please sign in to comment.