Skip to content

[CI] Pin pypa/gh-action-pypi-publish to allowed commit hash#2817

Merged
jbampton merged 1 commit intoapache:masterfrom
jiayuasu:worktree-fix+pin-pypi-publish-action
Mar 31, 2026
Merged

[CI] Pin pypa/gh-action-pypi-publish to allowed commit hash#2817
jbampton merged 1 commit intoapache:masterfrom
jiayuasu:worktree-fix+pin-pypi-publish-action

Conversation

@jiayuasu
Copy link
Copy Markdown
Member

Summary

  • Pin pypa/gh-action-pypi-publish from @release/v1 (branch ref) to @ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e (v1.13.0), which is the latest version in Apache's infrastructure-actions allowlist.
  • Remove the pypa/gh-action-pypi-publish: any exception from .github/linters/zizmor.yml since the action is now properly pinned to a commit hash.

Closes #2814

Pin pypa/gh-action-pypi-publish from @release/v1 branch ref to
@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e (v1.13.0), which is
required by Apache's infrastructure-actions allowlist.

Remove the zizmor unpinned-uses exception since the action is now
pinned to a commit hash.

Closes apache#2814
@jiayuasu jiayuasu requested a review from jbampton as a code owner March 31, 2026 08:55
@jbampton jbampton self-assigned this Mar 31, 2026
@jbampton jbampton added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code and removed dependencies Pull requests that update a dependency file labels Mar 31, 2026
@jbampton jbampton merged commit 5277604 into apache:master Mar 31, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The action pypa/gh-action-pypi-publish@release/v1 is not allowed in apache/sedona

2 participants