Skip to content

Commit

Permalink
Merge pull request #312 from ASFHyP3/dependabot/github_actions/pypa/g…
Browse files Browse the repository at this point in the history
…h-action-pypi-publish-1.12.4

Bump pypa/gh-action-pypi-publish from 1.12.3 to 1.12.4
  • Loading branch information
jtherrmann authored Feb 12, 2025
2 parents 1475630 + 83a42cc commit 948702f
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion .github/workflows/distribute.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ jobs:
python -m build
- name: upload to PyPI.org
uses: pypa/gh-action-pypi-publish@v1.12.3
uses: pypa/gh-action-pypi-publish@v1.12.4

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Distribute to PyPI' step
Uses Step
uses 'pypa/gh-action-pypi-publish' with ref 'v1.12.4', not a pinned commit hash
with:
user: __token__
password: ${{ secrets.TOOLS_PYPI_PAK }}

0 comments on commit 948702f

Please sign in to comment.