- Notifications
You must be signed in to change notification settings - Fork23
CI: Harden GHA configuration#308
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Uh oh!
There was an error while loading.Please reload this page.
Conversation
This eliminates the possibility of a tag being changed underus.
This eliminates the possibility of a tag being changed underus.
May include:- Avoids risky string interpolation.- Prevents checkout premissions from leaking
Reduces risk of arbitrary code is run by attacker.
tacaswell commentedJul 18, 2025
Seematplotlib/matplotlib#30045 but precommit.ci has been disabled at the org level, not sure what else needs to be done to get rid of the check. |
samcunliffe commentedJul 19, 2025
Looks like that worked! ![]() |
dstansby commentedJul 20, 2025
Thanks for this - I have removed pre-commit.ci as a required build, but for this PR will just bypass the rules and merge instead of trying to remvoe pre-commit.ci as a required check. |
64edb23 intomatplotlib:mainUh oh!
There was an error while loading.Please reload this page.

Apply recommended hardening steps including: