Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
97 commits
Select commit Hold shift + click to select a range
30ba791
build(deps): bump stevedore from 5.4.1 to 5.5.0 in /doc/assets
dependabot[bot] Oct 1, 2025
d396a3a
build(deps): bump ninja from 1.11.1.4 to 1.13.0 in /doc/assets
dependabot[bot] Oct 1, 2025
771bdac
build(deps): bump doc8 from 1.1.2 to 2.0.0 in /doc/assets
dependabot[bot] Oct 28, 2025
d8ea717
build(deps): bump dnspython from 2.7.0 to 2.8.0 in /doc/assets
dependabot[bot] Oct 28, 2025
b7862d0
build(deps): bump idna from 3.10 to 3.11 in /doc/assets
dependabot[bot] Oct 28, 2025
fd7313a
build(deps): bump github/codeql-action from 4.31.0 to 4.31.2
dependabot[bot] Oct 31, 2025
073d8c7
Merge pull request #583 from OZI-Project/2.3
rjdbcm Oct 31, 2025
0ad888c
Merge pull request #584 from OZI-Project/dependabot/github_actions/gi…
rjdbcm Oct 31, 2025
b937a4b
build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0
dependabot[bot] Dec 15, 2025
86b00b7
Merge pull request #537 from OZI-Project/dependabot/pip/doc/assets/st…
rjdbcm Mar 27, 2026
5c607fb
Merge pull request #598 from OZI-Project/dependabot/github_actions/ac…
rjdbcm Mar 27, 2026
5e395f4
build(deps): bump requests
dependabot[bot] Mar 27, 2026
5aa3c05
Merge pull request #599 from OZI-Project/dependabot/pip/doc/assets/de…
rjdbcm Mar 27, 2026
4339a2a
build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0
dependabot[bot] Mar 27, 2026
9d5a9a7
build(deps): bump pyparsing from 3.2.5 to 3.3.2 in /doc/assets
dependabot[bot] Mar 27, 2026
d29630b
build(deps): bump github/codeql-action from 4.31.2 to 4.34.1
dependabot[bot] Mar 27, 2026
25c4a02
build(deps): bump step-security/harden-runner from 2.13.1 to 2.16.0
dependabot[bot] Mar 27, 2026
eeaf195
build(deps): bump actions/checkout from 5.0.0 to 6.0.2
dependabot[bot] Mar 27, 2026
c7430e9
build(deps): bump soupsieve from 2.7 to 2.8.3 in /doc/assets
dependabot[bot] Mar 27, 2026
7a5a3f5
fix: update ozi.wrap wrapfile
rjdbcm Mar 27, 2026
0a8ae75
fix: add '--clear' option to uv postconf script
rjdbcm Mar 27, 2026
7b8abda
Merge pull request #613 from OZI-Project/rjdbcm-patch-7
rjdbcm Mar 27, 2026
332cd75
Merge pull request #612 from OZI-Project/update-wrapfile
rjdbcm Mar 27, 2026
2b0f6af
Merge pull request #580 from OZI-Project/dependabot/pip/doc/assets/id…
rjdbcm Mar 27, 2026
2bb89b9
Merge pull request #600 from OZI-Project/dependabot/github_actions/ac…
rjdbcm Mar 27, 2026
6adddd2
build(deps): bump charset-normalizer from 3.4.3 to 3.4.6 in /doc/assets
dependabot[bot] Mar 27, 2026
b2bc6c0
Merge pull request #609 from OZI-Project/dependabot/pip/doc/assets/ch…
rjdbcm Mar 27, 2026
9cd13de
Merge pull request #607 from OZI-Project/dependabot/github_actions/ac…
rjdbcm Mar 27, 2026
32c1d4f
build(deps): bump actions/dependency-review-action from 4.8.1 to 4.9.0
dependabot[bot] Mar 27, 2026
12a1b35
build(deps): bump pip-tools from 7.5.0 to 7.5.3 in /doc/assets
dependabot[bot] Mar 27, 2026
897569a
Merge pull request #605 from OZI-Project/dependabot/github_actions/ac…
rjdbcm Mar 27, 2026
d1b6198
Merge pull request #603 from OZI-Project/dependabot/github_actions/gi…
rjdbcm Mar 27, 2026
8056d34
Merge pull request #606 from OZI-Project/dependabot/github_actions/st…
rjdbcm Mar 27, 2026
b84a755
Merge pull request #543 from OZI-Project/dependabot/pip/doc/assets/ni…
rjdbcm Mar 27, 2026
9a10a5c
Merge pull request #608 from OZI-Project/dependabot/pip/doc/assets/so…
rjdbcm Mar 27, 2026
29a1551
Merge pull request #610 from OZI-Project/dependabot/pip/doc/assets/pi…
rjdbcm Mar 27, 2026
42ae5c6
Merge pull request #578 from OZI-Project/dependabot/pip/doc/assets/dn…
rjdbcm Mar 27, 2026
f58bf39
Merge pull request #601 from OZI-Project/dependabot/pip/doc/assets/py…
rjdbcm Mar 27, 2026
0beb0d5
Merge pull request #573 from OZI-Project/dependabot/pip/doc/assets/do…
rjdbcm Mar 27, 2026
f0cbc01
build(deps): bump sphinx from 7.4.7 to 9.1.0 in /doc/assets
dependabot[bot] Mar 27, 2026
34649eb
Merge pull request #604 from OZI-Project/dependabot/pip/doc/assets/sp…
rjdbcm Mar 27, 2026
441fb5d
build(deps): bump OZI-Project/publish from 1.17.4 to 2.0.0
dependabot[bot] Mar 27, 2026
c1f7975
build(deps): bump actions/download-artifact from 6.0.0 to 8.0.1
dependabot[bot] Mar 27, 2026
90fa842
build(deps): bump OZI-Project/provenance from 1.1.0 to 2.0.0
dependabot[bot] Mar 27, 2026
e6e6e97
build(deps): bump gitpython from 3.1.45 to 3.1.46 in /doc/assets
dependabot[bot] Mar 27, 2026
d3aef53
build(deps): bump beautifulsoup4 from 4.14.2 to 4.14.3 in /doc/assets
dependabot[bot] Mar 27, 2026
9c570dc
build(deps): bump OZI-Project/draft from 1.17.4 to 2.0.0
dependabot[bot] Mar 27, 2026
361b3c1
build(deps): bump click from 8.3.0 to 8.3.1 in /doc/assets
dependabot[bot] Mar 27, 2026
952bcd0
build(deps): bump babel from 2.17.0 to 2.18.0 in /doc/assets
dependabot[bot] Mar 27, 2026
e1dd669
build(deps): bump certifi from 2025.10.5 to 2026.2.25 in /doc/assets
dependabot[bot] Mar 27, 2026
a830ab0
build(deps): bump pbr from 7.0.1 to 7.0.3 in /doc/assets
dependabot[bot] Mar 27, 2026
5f36cb0
build(deps): bump smmap from 5.0.2 to 5.0.3 in /doc/assets
dependabot[bot] Mar 27, 2026
50aae36
build(deps): bump restructuredtext-lint in /doc/assets
dependabot[bot] Mar 27, 2026
2e7ed70
Merge pull request #615 from OZI-Project/dependabot/github_actions/ac…
rjdbcm Mar 27, 2026
9b9931a
Merge pull request #625 from OZI-Project/dependabot/pip/doc/assets/sm…
rjdbcm Mar 27, 2026
a0af559
Merge pull request #618 from OZI-Project/dependabot/pip/doc/assets/be…
rjdbcm Mar 27, 2026
f3e142b
Merge pull request #622 from OZI-Project/dependabot/pip/doc/assets/ba…
rjdbcm Mar 27, 2026
7edbc40
Merge pull request #623 from OZI-Project/dependabot/pip/doc/assets/ce…
rjdbcm Mar 27, 2026
b075e48
Merge pull request #620 from OZI-Project/dependabot/pip/doc/assets/cl…
rjdbcm Mar 27, 2026
fdc4d0d
Merge pull request #624 from OZI-Project/dependabot/pip/doc/assets/pb…
rjdbcm Mar 27, 2026
c436307
Merge pull request #617 from OZI-Project/dependabot/pip/doc/assets/gi…
rjdbcm Mar 27, 2026
1731f3d
Update sphinx-design version to 0.7.0
rjdbcm Mar 27, 2026
9ddd7b8
Merge pull request #628 from OZI-Project/rjdbcm-patch-8
rjdbcm Mar 27, 2026
2b48ddc
build(deps): bump wcwidth from 0.2.14 to 0.6.0 in /doc/assets
dependabot[bot] Mar 27, 2026
c804597
build(deps): bump packaging from 25.0 to 26.0 in /doc/assets
dependabot[bot] Mar 27, 2026
154f128
build(deps): bump stevedore from 5.5.0 to 5.7.0 in /doc/assets
dependabot[bot] Mar 27, 2026
532c223
build(deps): bump docutils from 0.21.2 to 0.22.4 in /doc/assets
dependabot[bot] Mar 27, 2026
7c3d884
Update sphinxawesome-codelinter to version 3.0.1
rjdbcm Mar 27, 2026
65aa498
Merge pull request #636 from OZI-Project/rjdbcm-patch-8
rjdbcm Mar 27, 2026
f1c0948
build(deps): bump sphinxawesome-theme from 5.3.2 to 6.0.0 in /doc/assets
dependabot[bot] Mar 27, 2026
c9a8c74
Merge pull request #633 from OZI-Project/dependabot/pip/doc/assets/pa…
rjdbcm Mar 27, 2026
52adf59
Merge pull request #631 from OZI-Project/dependabot/pip/doc/assets/sp…
rjdbcm Mar 27, 2026
c3df41b
Merge pull request #632 from OZI-Project/dependabot/pip/doc/assets/wc…
rjdbcm Mar 27, 2026
f0b74be
build(deps): bump urllib3 from 2.5.0 to 2.6.3 in /doc/assets
dependabot[bot] Mar 27, 2026
52a9272
build(deps): bump OZI-Project/secure-release from 1.2.0 to 2.0.0
dependabot[bot] Mar 27, 2026
c49a965
build(deps): bump wheel from 0.46.1 to 0.46.3 in /doc/assets
dependabot[bot] Mar 27, 2026
3ae0cbb
build(deps): bump build from 1.3.0 to 1.4.2 in /doc/assets
dependabot[bot] Mar 27, 2026
853a1e5
build(deps): bump OZI-Project/checkpoint from 1.11.0 to 2.0.2
dependabot[bot] Mar 27, 2026
7470f92
build(deps): bump imagesize from 1.4.1 to 2.0.0 in /doc/assets
dependabot[bot] Mar 27, 2026
4fd12a5
build(deps): bump sphinxcontrib-programoutput in /doc/assets
dependabot[bot] Mar 27, 2026
ce9d0eb
build(deps): bump meson from 1.9.1 to 1.10.2 in /doc/assets
dependabot[bot] Mar 27, 2026
86466e0
Merge pull request #641 from OZI-Project/dependabot/github_actions/OZ…
rjdbcm Mar 27, 2026
851ec5b
Merge pull request #643 from OZI-Project/dependabot/pip/doc/assets/sp…
rjdbcm Mar 27, 2026
8d1e5b6
Merge pull request #644 from OZI-Project/dependabot/pip/doc/assets/me…
rjdbcm Mar 27, 2026
dbdf78f
Merge pull request #637 from OZI-Project/dependabot/github_actions/OZ…
rjdbcm Mar 27, 2026
13065f1
Merge pull request #640 from OZI-Project/dependabot/pip/doc/assets/bu…
rjdbcm Mar 27, 2026
40eccaa
Merge pull request #642 from OZI-Project/dependabot/pip/doc/assets/im…
rjdbcm Mar 27, 2026
1243975
build(deps): bump github/codeql-action from 4.34.1 to 4.35.1
dependabot[bot] Mar 27, 2026
1cf2f8d
Merge pull request #634 from OZI-Project/dependabot/pip/doc/assets/ur…
rjdbcm Mar 27, 2026
6fc73a1
Merge pull request #639 from OZI-Project/dependabot/pip/doc/assets/wh…
rjdbcm Mar 27, 2026
995e52f
Merge pull request #635 from OZI-Project/dependabot/pip/doc/assets/st…
rjdbcm Mar 27, 2026
aa8d048
Merge pull request #626 from OZI-Project/dependabot/pip/doc/assets/re…
rjdbcm Mar 27, 2026
feef671
Merge pull request #611 from OZI-Project/dependabot/pip/doc/assets/do…
rjdbcm Mar 27, 2026
a22f120
Merge pull request #619 from OZI-Project/dependabot/github_actions/OZ…
rjdbcm Mar 27, 2026
47d18fb
Merge pull request #616 from OZI-Project/dependabot/github_actions/OZ…
rjdbcm Mar 27, 2026
9743a59
Merge pull request #614 from OZI-Project/dependabot/github_actions/OZ…
rjdbcm Mar 27, 2026
21eaea4
Merge pull request #646 from OZI-Project/dependabot/github_actions/gi…
rjdbcm Mar 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/cleanup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
steps:

- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
egress-policy: audit

Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,16 +41,16 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
egress-policy: audit

- name: Checkout repository
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@4e94bd11f71e507f7f87df81788dff88d1dacbfb # v4.31.0
uses: github/codeql-action/init@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
Expand All @@ -60,7 +60,7 @@ jobs:
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@4e94bd11f71e507f7f87df81788dff88d1dacbfb # v4.31.0
uses: github/codeql-action/autobuild@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1

# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
Expand All @@ -73,6 +73,6 @@ jobs:
# ./location_of_script_within_repo/buildscript.sh

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@4e94bd11f71e507f7f87df81788dff88d1dacbfb # v4.31.0
uses: github/codeql-action/analyze@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1
with:
category: "/language:${{matrix.language}}"
6 changes: 3 additions & 3 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,11 +17,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
egress-policy: audit

- name: 'Checkout Repository'
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: 'Dependency Review'
uses: actions/dependency-review-action@40c09b7dc99638e5ddb0bfd91c1673effc064d8a # v4.8.1
uses: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4.9.0
16 changes: 8 additions & 8 deletions .github/workflows/dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -39,7 +39,7 @@ jobs:
dev-87evx9ru.auth0.com:443
release-assets.githubusercontent.com:443

- uses: OZI-Project/checkpoint@5c04e23edea0edcd1eb731ad465d3fb7fe5ad0d7 # 1.11.0
- uses: OZI-Project/checkpoint@79488fc5941940c6d14be5968e58a9191eb6b922 # 2.0.2
with:
python-version: "3.10"

Expand All @@ -52,7 +52,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -72,7 +72,7 @@ jobs:
dev-87evx9ru.auth0.com:443
release-assets.githubusercontent.com:443

- uses: OZI-Project/checkpoint@5c04e23edea0edcd1eb731ad465d3fb7fe5ad0d7 # 1.11.0
- uses: OZI-Project/checkpoint@79488fc5941940c6d14be5968e58a9191eb6b922 # 2.0.2
with:
python-version: "3.11"

Expand All @@ -85,7 +85,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -105,7 +105,7 @@ jobs:
dev-87evx9ru.auth0.com:443
release-assets.githubusercontent.com:443

- uses: OZI-Project/checkpoint@5c04e23edea0edcd1eb731ad465d3fb7fe5ad0d7 # 1.11.0
- uses: OZI-Project/checkpoint@79488fc5941940c6d14be5968e58a9191eb6b922 # 2.0.2
with:
python-version: "3.12"

Expand All @@ -118,7 +118,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -139,6 +139,6 @@ jobs:
dev-87evx9ru.auth0.com:443
release-assets.githubusercontent.com:443

- uses: OZI-Project/checkpoint@5c04e23edea0edcd1eb731ad465d3fb7fe5ad0d7
- uses: OZI-Project/checkpoint@79488fc5941940c6d14be5968e58a9191eb6b922
with:
python-version: "3.13"
34 changes: 17 additions & 17 deletions .github/workflows/ozi.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -40,7 +40,7 @@ jobs:
dev-87evx9ru.auth0.com:443
release-assets.githubusercontent.com:443

- uses: OZI-Project/checkpoint@5c04e23edea0edcd1eb731ad465d3fb7fe5ad0d7 # 1.11.0
- uses: OZI-Project/checkpoint@79488fc5941940c6d14be5968e58a9191eb6b922 # 2.0.2
with:
python-version: "3.10"

Expand All @@ -53,7 +53,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -72,7 +72,7 @@ jobs:
dev-87evx9ru.auth0.com:443
release-assets.githubusercontent.com:443

- uses: OZI-Project/checkpoint@5c04e23edea0edcd1eb731ad465d3fb7fe5ad0d7 # 1.11.0
- uses: OZI-Project/checkpoint@79488fc5941940c6d14be5968e58a9191eb6b922 # 2.0.2
with:
python-version: "3.11"

Expand All @@ -85,7 +85,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -104,7 +104,7 @@ jobs:
dev-87evx9ru.auth0.com:443
release-assets.githubusercontent.com:443

- uses: OZI-Project/checkpoint@5c04e23edea0edcd1eb731ad465d3fb7fe5ad0d7 # 1.11.0
- uses: OZI-Project/checkpoint@79488fc5941940c6d14be5968e58a9191eb6b922 # 2.0.2
with:
python-version: "3.12"

Expand All @@ -114,7 +114,7 @@ jobs:
needs: [checkpoint-cp310-ubuntu-latest,checkpoint-cp311-ubuntu-latest,checkpoint-cp312-ubuntu-latest,]
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -134,15 +134,15 @@ jobs:
tag: ${{ steps.draft.outputs.tag }}
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
allowed-endpoints: >
api.github.com:443
github.com:443

- uses: OZI-Project/draft@d1cca28d3fa7f004b7b21abcb945e6760246bae7 # 1.17.4
- uses: OZI-Project/draft@bdf835e591fec9e11b421f11e6ed271fb32c1211 # 2.0.0
id: draft
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -160,7 +160,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -179,7 +179,7 @@ jobs:
cdn03.quay.io:443
downloads.python.org:443

- uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6.0.0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: security2

Expand Down Expand Up @@ -217,12 +217,12 @@ jobs:
run: tox -e invoke -- --list

- name: Publish release
uses: OZI-Project/secure-release@2ef1b3f4b10f3fee22ba26444a6324203d6e2ea4 # 1.2.0
uses: OZI-Project/secure-release@d9ce4269658c1c941c592254e9c3ba1cb9fd0d3e # 2.0.0
with:
sdist: true
wheel-sign-token: ${{ secrets.WHEEL_SIGN_TOKEN }}

- uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
- uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
include-hidden-files: true
path: |
Expand All @@ -242,7 +242,7 @@ jobs:
id-token: write
attestations: write
steps:
- uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
- uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -257,7 +257,7 @@ jobs:
ghcr.io:443
pkg-containers.githubusercontent.com:443

- uses: OZI-Project/provenance@96f6b35116d8140aaa0415fe31dddc4a4a84af2d
- uses: OZI-Project/provenance@0c9501b316d7b2311e07e6c349c6465df3eed63e
with:
release-tag: ${{ needs.draft.outputs.tag }}

Expand All @@ -271,7 +271,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -286,7 +286,7 @@ jobs:
ghcr.io:443
pkg-containers.githubusercontent.com:443

- uses: OZI-Project/publish@4ec8a034b233d85270e2b80ab567b1691f708b02 # 1.17.4
- uses: OZI-Project/publish@4721026c54c563e7d21133eedd0ed6f327af3f81 # 2.0.0
with:
github-token: ${{ secrets.GITHUB_TOKEN }}

Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/scorecards.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
disable-sudo: true
egress-policy: block
Expand All @@ -49,7 +49,7 @@ jobs:
www.bestpractices.dev:443

- name: "Checkout code"
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

Expand All @@ -76,14 +76,14 @@ jobs:
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
- name: "Upload artifact"
uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
name: SARIF file
path: results.sarif
retention-days: 5

# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@4e94bd11f71e507f7f87df81788dff88d1dacbfb # v4.31.0
uses: github/codeql-action/upload-sarif@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1
with:
sarif_file: results.sarif
Loading
Loading