Skip to content

Commit 5255127

Browse files
Merge branch 'main' into open-dataset
2 parents feb67c1 + 63f60fe commit 5255127

3 files changed

Lines changed: 17 additions & 1 deletion

File tree

.github/workflows/ci.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -243,3 +243,17 @@ jobs:
243243
done
244244
env:
245245
PREFIX_API_KEY: ${{ secrets.PREFIX_API_KEY }} # zizmor: ignore[secrets-outside-env]
246+
247+
zizmor:
248+
name: GHA Security Analysis using Zizmor
249+
runs-on: ubuntu-latest
250+
permissions:
251+
security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files.
252+
steps:
253+
- name: Checkout repository
254+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
255+
with:
256+
persist-credentials: false
257+
258+
- name: Run zizmor
259+
uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2

.pre-commit-config.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ repos:
1313
rev: v1.23.1
1414
hooks:
1515
- id: zizmor
16+
args: ["--offline"]
1617
- repo: https://github.com/astral-sh/ruff-pre-commit
1718
rev: v0.15.9
1819
hooks:

pixi.toml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,10 @@
11
[workspace]
22
name = "Parcels"
3+
exclude-newer = "5d" # security pre-caution against compromised packages
34
preview = ["pixi-build"]
45
channels = ["conda-forge"]
56
platforms = ["win-64", "linux-64", "osx-64", "osx-arm64"]
6-
requires-pixi = ">=0.63.0"
7+
requires-pixi = ">=0.67.0"
78

89
[package]
910
name = "parcels"

0 commit comments

Comments
 (0)