Skip to content

Comments

address CI issues reported by zizmor#892

Merged
loosebazooka merged 3 commits intosigstore:mainfrom
bobcallaway:zizmor
Jan 23, 2025
Merged

address CI issues reported by zizmor#892
loosebazooka merged 3 commits intosigstore:mainfrom
bobcallaway:zizmor

Conversation

@bobcallaway
Copy link
Member

pins actions, stops persisting git credentials, and removes template injection risk.

Signed-off-by: Bob Callaway <bcallaway@google.com>
loosebazooka
loosebazooka previously approved these changes Jan 22, 2025
Signed-off-by: Appu <appu@google.com>
@loosebazooka
Copy link
Member

loosebazooka commented Jan 22, 2025

oh examples is failing on a fork. I see, this isn't a real problem. Maybe we should use the oidc token from sigstore-conformance for forked PRs

Signed-off-by: Appu <appu@google.com>
@loosebazooka loosebazooka merged commit 680fccf into sigstore:main Jan 23, 2025
12 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants