zizmor: Full security lint of publish-to-pypi.yml - #2107
Conversation
| name: Publish Python 🐍 distribution 📦 to PyPI and TestPyPI | ||
|
|
||
| on: push | ||
| permissions: {} |
There was a problem hiding this comment.
This one might be okay provided the build job also lists the exact privileges required and the PR is scoped to only adding permissions: to examples.
Also, add one empty-line separator above.
|
Closing in favor of #2106 because we want to keep the |
|
@cclauss it's probably still a good idea to tell users to use Zizmor in some tip admonition in the guide, though, if it still doesn't do that. One important thing that people miss in my experience is separating the publishing and the building jobs, though. Showing different explicit permissions might be a good hint for them. Unfortunately, it seems like they tend to copy their examples from some weird projects on the internet that already don't follow this recommendation. |
|
I find I agree that bad examples abound, but I believe that these samples should be the source of truth for visitors. If this repo were to adopt Dependabot for GitHub Actions with a 7-day cooldown plus full Zizmor, then these samples could be best-practice examples that use current actions and pass Zizmor. I know this is more PRs for maintainers to review and merge, but at least visitors would not be misled. |
A superset of #2106 that passes zizmor security linting checks.
@webknjaz Your review, please.
📚 Documentation preview 📚: https://python-packaging-user-guide--2107.org.readthedocs.build/en/2107/