From f6a7af63b988b216e353eb42dc22249d445bda63 Mon Sep 17 00:00:00 2001 From: andrewpollack Date: Sun, 8 Jun 2025 08:19:08 -0700 Subject: [PATCH] security: pin version of py-actions/py-dependency-install Remeidates: https://docs.zizmor.sh/audits/#impostor-commit Version: https://github.com/py-actions/py-dependency-install/releases/tag/v4.0.0 --- .github/workflows/checks.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/checks.yml b/.github/workflows/checks.yml index 20455297..a231ef4c 100644 --- a/.github/workflows/checks.yml +++ b/.github/workflows/checks.yml @@ -6,6 +6,7 @@ permissions: jobs: Run-Markdown-Checks: + name: Run Markdown Checks runs-on: ubuntu-24.04 steps: - name: checkout @@ -13,7 +14,7 @@ jobs: with: persist-credentials: false - name: Install Python dependencies - uses: py-actions/py-dependency-install@v4 + uses: py-actions/py-dependency-install@9c419aa98bfb42280bdae2b0a736befd9b01e3b1 # v4 with: path: "tools/requirements.txt" update-pip: "false"