Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -20,9 +20,9 @@
- "*"

permissions:
id-token: write

Check failure on line 23 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

excessive-permissions

release.yaml:23: overly broad permissions: id-token: write is overly broad at the workflow level
contents: write

Check failure on line 24 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

excessive-permissions

release.yaml:24: overly broad permissions: contents: write is overly broad at the workflow level
packages: write

Check failure on line 25 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

excessive-permissions

release.yaml:25: overly broad permissions: packages: write is overly broad at the workflow level

jobs:
release:
Expand All @@ -30,27 +30,27 @@
if: startsWith(github.ref, 'refs/tags/')
steps:
- name: Checkout repo
uses: actions/checkout@v4

Check failure on line 33 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 33 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

unpinned-uses

release.yaml:33: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
fetch-depth: 0
- name: Setup Go
uses: actions/setup-go@v5

Check failure on line 37 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 37 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

unpinned-uses

release.yaml:37: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
go-version: 1.24
go-version-file: .go-version
check-latest: true
cache: true
- name: Install Cosign
uses: sigstore/cosign-installer@v3

Check failure on line 43 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 43 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

unpinned-uses

release.yaml:43: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
cosign-release: 'v2.4.0'
- name: Build and package with GoReleaser
uses: goreleaser/goreleaser-action@v6

Check failure on line 47 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 47 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

unpinned-uses

release.yaml:47: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
distribution: goreleaser
version: latest
args: --skip=publish
- name: Release
uses: softprops/action-gh-release@v2

Check failure on line 53 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check notice on line 53 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

superfluous-actions

release.yaml:53: action functionality is already included by the runner: use `gh release` in a script step

Check failure on line 53 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

unpinned-uses

release.yaml:53: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
files: |
dist/checksums.txt
Expand All @@ -62,21 +62,21 @@
runs-on: ubuntu-latest
steps:
- name: Login to GHCR
uses: docker/login-action@v3

Check failure on line 65 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 65 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

unpinned-uses

release.yaml:65: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Set up QEMU
uses: docker/setup-qemu-action@v3

Check failure on line 72 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 72 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

unpinned-uses

release.yaml:72: unpinned action reference: action is not pinned to a hash (required by blanket policy)

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

Check failure on line 75 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)

- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5

Check failure on line 79 in .github/workflows/release.yaml

View workflow job for this annotation

GitHub Actions / zizmor-output

zizmor/unpinned-uses

unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
images: ghcr.io/${{ github.repository }}
tags: |
Expand Down
1 change: 1 addition & 0 deletions .go-version
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
1.27.1
2 changes: 1 addition & 1 deletion go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ module github.com/google/yamlfmt

go 1.22

toolchain go1.24.8
toolchain go1.27.1

require (
github.com/bmatcuk/doublestar/v4 v4.7.1
Expand Down
Loading