Merge pull request #549 from crazy-max/zizmor-fixes
Some checks are pending
ci / main (v0.4.1) (push) Waiting to run
ci / multi (push) Waiting to run
ci / main () (push) Waiting to run
test / test (push) Waiting to run
ci / windows-error (push) Waiting to run
ci / keep-state (push) Waiting to run
ci / keep-state-error (push) Waiting to run
ci / main (cloud:latest) (push) Waiting to run
ci / main (cloud:v0.11.2-desktop.2) (push) Waiting to run
ci / main (lab:latest) (push) Waiting to run
ci / main (latest) (push) Waiting to run
ci / error (push) Waiting to run
ci / debug (push) Waiting to run
ci / use (false) (push) Waiting to run
ci / use (true) (push) Waiting to run
ci / driver (image=moby/buildkit:latest) (push) Waiting to run
ci / driver (image=moby/buildkit:master network=host ) (push) Waiting to run
ci / docker-driver (push) Waiting to run
ci / endpoint (push) Waiting to run
ci / buildkitd-config (push) Waiting to run
ci / buildkitd-config-inline (push) Waiting to run
ci / with-qemu (, all) (push) Waiting to run
ci / with-qemu (, arm64,riscv64,arm) (push) Waiting to run
ci / with-qemu (v0.9.1, all) (push) Waiting to run
ci / with-qemu (v0.9.1, arm64,riscv64,arm) (push) Waiting to run
ci / build-ref (cb185f095fd3d9444e0aa605d3789e9e05f2a1e7) (push) Waiting to run
ci / build-ref (master) (push) Waiting to run
ci / build-ref (refs/pull/731/head) (push) Waiting to run
ci / build-ref (refs/tags/v0.5.1) (push) Waiting to run
ci / standalone-cmd (push) Waiting to run
ci / standalone-action (push) Waiting to run
ci / append (push) Waiting to run
ci / platforms (push) Waiting to run
ci / docker-context (push) Waiting to run
ci / cleanup (false) (push) Waiting to run
ci / cleanup (true) (push) Waiting to run
ci / k3s (latest) (push) Waiting to run
ci / k3s (v0.10.5) (push) Waiting to run
ci / k3s (v0.11.0) (push) Waiting to run
ci / cache-binary (false) (push) Waiting to run
ci / cache-binary (true) (push) Waiting to run
codeql / analyze (push) Waiting to run
validate / prepare (push) Waiting to run
validate / validate (push) Blocked by required conditions
zizmor / zizmor (push) Waiting to run

ci: restrict update-dist GitHub App token scope
This commit is contained in:
CrazyMax 2026-05-21 14:58:05 +02:00 committed by GitHub
commit fe05060e96
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -26,6 +26,8 @@ jobs:
app-id: ${{ secrets.GHACTIONS_REPO_WRITE_APP_ID }}
private-key: ${{ secrets.GHACTIONS_REPO_WRITE_APP_PRIVATE_KEY }}
owner: docker
repositories: setup-buildx-action
permission-contents: write
-
name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2