diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f741ba8a..a059fb69 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -31,7 +31,7 @@ permissions: {} jobs: core: - uses: OpenAstronomy/github-actions-workflows/.github/workflows/tox.yml@v2 # zizmor: ignore[unpinned-uses] + uses: OpenAstronomy/github-actions-workflows/.github/workflows/tox.yml@v2.6.3 # zizmor: ignore[unpinned-uses] with: submodules: false coverage: codecov @@ -45,7 +45,7 @@ jobs: sdist_verify: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 # zizmor: ignore[unpinned-uses] + - uses: actions/checkout@v6.0.2 # zizmor: ignore[unpinned-uses] with: persist-credentials: false - uses: actions/setup-python@v6 # zizmor: ignore[unpinned-uses] @@ -58,7 +58,7 @@ jobs: test: needs: [core, sdist_verify] - uses: OpenAstronomy/github-actions-workflows/.github/workflows/tox.yml@v2 # zizmor: ignore[unpinned-uses] + uses: OpenAstronomy/github-actions-workflows/.github/workflows/tox.yml@v2.6.3 # zizmor: ignore[unpinned-uses] with: submodules: false coverage: codecov @@ -75,7 +75,7 @@ jobs: docs: needs: [core] - uses: OpenAstronomy/github-actions-workflows/.github/workflows/tox.yml@v2 # zizmor: ignore[unpinned-uses] + uses: OpenAstronomy/github-actions-workflows/.github/workflows/tox.yml@v2.6.3 # zizmor: ignore[unpinned-uses] with: default_python: '3.13' submodules: false @@ -90,7 +90,7 @@ jobs: online: if: "!startsWith(github.event.ref, 'refs/tags/v')" needs: [test] - uses: OpenAstronomy/github-actions-workflows/.github/workflows/tox.yml@v2 # zizmor: ignore[unpinned-uses] + uses: OpenAstronomy/github-actions-workflows/.github/workflows/tox.yml@v2.6.3 # zizmor: ignore[unpinned-uses] with: default_python: '3.13' submodules: false @@ -112,7 +112,7 @@ jobs: contains(github.event.pull_request.labels.*.name, 'Run publish') ) needs: [test, docs] - uses: OpenAstronomy/github-actions-workflows/.github/workflows/publish_pure_python.yml@v2 # zizmor: ignore[unpinned-uses] + uses: OpenAstronomy/github-actions-workflows/.github/workflows/publish_pure_python.yml@v2.6.3 # zizmor: ignore[unpinned-uses] with: python-version: '3.13' test_extras: 'tests' diff --git a/.github/workflows/sub_package_update.yml b/.github/workflows/sub_package_update.yml index bfb213a8..7c98feaf 100644 --- a/.github/workflows/sub_package_update.yml +++ b/.github/workflows/sub_package_update.yml @@ -22,7 +22,7 @@ jobs: contents: write pull-requests: write steps: - - uses: actions/checkout@v6 # zizmor: ignore[unpinned-uses] + - uses: actions/checkout@v6.0.2 # zizmor: ignore[unpinned-uses] with: persist-credentials: false