Skip to content

Commit dd16f89

Browse files
committed
📦🔒️ Add persist-credentials: false to GitHub Actions checkout steps
1 parent c9e2dc5 commit dd16f89

1 file changed

Lines changed: 10 additions & 0 deletions

File tree

project_name/.github/workflows/ci.yml.jinja

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,8 @@ jobs:
1717
runs-on: ubuntu-latest
1818
steps:
1919
- uses: actions/checkout@v4
20+
with:
21+
persist-credentials: false
2022
- uses: psf/black@stable
2123
with:
2224
jupyter: {{ "true" if contains_jupyter_files else "false" }}
@@ -28,6 +30,8 @@ jobs:
2830
runs-on: ubuntu-latest
2931
steps:
3032
- uses: actions/checkout@v4
33+
with:
34+
persist-credentials: false
3135
- uses: astral-sh/ruff-action@v3
3236
with:
3337
args: "format --check"
@@ -38,6 +42,8 @@ jobs:
3842
runs-on: ubuntu-latest
3943
steps:
4044
- uses: actions/checkout@v4
45+
with:
46+
persist-credentials: false
4147
- uses: astral-sh/ruff-action@v3
4248

4349
pre-commit:
@@ -47,13 +53,17 @@ jobs:
4753
runs-on: ubuntu-latest
4854
steps:
4955
- uses: actions/checkout@v4
56+
with:
57+
persist-credentials: false
5058
- uses: pre-commit/action@v3.0.1
5159

5260
mypy:
5361
if: {% raw %}${{ always() }}{% endraw %}
5462
runs-on: ubuntu-latest
5563
steps:
5664
- uses: actions/checkout@v4
65+
with:
66+
persist-credentials: false
5767
- uses: astral-sh/setup-uv@v6
5868
- name: Install packages
5969
run: >-

0 commit comments

Comments
 (0)