Commit 9c596da
committed
ci: bump zizmor-action to v0.5.6 and disable uv cache in release build
The newer zizmor (1.25.x, shipped by zizmor-action v0.5.6) adds a
cache-poisoning audit that flags astral-sh/setup-uv with
enable-cache: true in a release: published-triggered job. Disable the
cache for the release-build job - release builds are infrequent and a
cold cache is fine - so the new security workflow lands clean.1 parent eb9745b commit 9c596da
2 files changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
0 commit comments