From 2d1045d9e659c2d324bce800aa4830f11cf11a3f Mon Sep 17 00:00:00 2001 From: Vincent MEURISSE Date: Tue, 14 Apr 2026 07:36:00 +0200 Subject: [PATCH 1/2] ci: add hk linter --- mise.lock | 202 +++++++++++++++++++++++++++++++++++++++++++++++++++--- mise.toml | 14 +++- 2 files changed, 206 insertions(+), 10 deletions(-) diff --git a/mise.lock b/mise.lock index 0bdeae7..5b4bda1 100644 --- a/mise.lock +++ b/mise.lock @@ -1,5 +1,44 @@ # @generated - this file is auto-generated by `mise lock` https://mise.jdx.dev/dev-tools/mise-lock.html +[[tools.actionlint]] +version = "1.7.11" +backend = "aqua:rhysd/actionlint" + +[tools.actionlint."platforms.linux-arm64"] +checksum = "sha256:21bc0dfb57a913fe175298c2a9e906ee630f747cb66d0a934d0d4b69f4ee1235" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.11/actionlint_1.7.11_linux_arm64.tar.gz" +provenance = "github-attestations" + +[tools.actionlint."platforms.linux-arm64-musl"] +checksum = "sha256:21bc0dfb57a913fe175298c2a9e906ee630f747cb66d0a934d0d4b69f4ee1235" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.11/actionlint_1.7.11_linux_arm64.tar.gz" +provenance = "github-attestations" + +[tools.actionlint."platforms.linux-x64"] +checksum = "sha256:900919a84f2229bac68ca9cd4103ea297abc35e9689ebb842c6e34a3d1b01b0a" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.11/actionlint_1.7.11_linux_amd64.tar.gz" +provenance = "github-attestations" + +[tools.actionlint."platforms.linux-x64-musl"] +checksum = "sha256:900919a84f2229bac68ca9cd4103ea297abc35e9689ebb842c6e34a3d1b01b0a" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.11/actionlint_1.7.11_linux_amd64.tar.gz" +provenance = "github-attestations" + +[tools.actionlint."platforms.macos-arm64"] +checksum = "sha256:a21ba7366d8329e7223faee0ed69eb13da27fe8acabb356bb7eb0b7f1e1cb6d8" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.11/actionlint_1.7.11_darwin_arm64.tar.gz" +provenance = "github-attestations" + +[tools.actionlint."platforms.macos-x64"] +checksum = "sha256:17ffc17fed8f0258ef6ad4aed932d3272464c7ef7d64e1cb0d65aa97c9752107" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.11/actionlint_1.7.11_darwin_amd64.tar.gz" +provenance = "github-attestations" + +[tools.actionlint."platforms.windows-x64"] +checksum = "sha256:5414b7124a91f4b5abee62e5c9d84802237734f8d15b9b7032732a32c3ebffa3" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.11/actionlint_1.7.11_windows_amd64.zip" +provenance = "github-attestations" + [[tools."github:CycloneDX/cyclonedx-gomod"]] version = "1.10.0" backend = "github:CycloneDX/cyclonedx-gomod" @@ -124,30 +163,37 @@ backend = "aqua:golangci/golangci-lint" [tools.golangci-lint."platforms.linux-arm64"] checksum = "sha256:3bcfa2e6f3d32b2bf5cd75eaa876447507025e0303698633f722a05331988db4" url = "https://github.com/golangci/golangci-lint/releases/download/v2.11.4/golangci-lint-2.11.4-linux-arm64.tar.gz" +provenance = "github-attestations" [tools.golangci-lint."platforms.linux-arm64-musl"] checksum = "sha256:3bcfa2e6f3d32b2bf5cd75eaa876447507025e0303698633f722a05331988db4" url = "https://github.com/golangci/golangci-lint/releases/download/v2.11.4/golangci-lint-2.11.4-linux-arm64.tar.gz" +provenance = "github-attestations" [tools.golangci-lint."platforms.linux-x64"] checksum = "sha256:200c5b7503f67b59a6743ccf32133026c174e272b930ee79aa2aa6f37aca7ef1" url = "https://github.com/golangci/golangci-lint/releases/download/v2.11.4/golangci-lint-2.11.4-linux-amd64.tar.gz" +provenance = "github-attestations" [tools.golangci-lint."platforms.linux-x64-musl"] checksum = "sha256:200c5b7503f67b59a6743ccf32133026c174e272b930ee79aa2aa6f37aca7ef1" url = "https://github.com/golangci/golangci-lint/releases/download/v2.11.4/golangci-lint-2.11.4-linux-amd64.tar.gz" +provenance = "github-attestations" [tools.golangci-lint."platforms.macos-arm64"] checksum = "sha256:02db2a2dae8b26812e53b0688a6f617e3ef1f489790e829ea22862cf76945675" url = "https://github.com/golangci/golangci-lint/releases/download/v2.11.4/golangci-lint-2.11.4-darwin-arm64.tar.gz" +provenance = "github-attestations" [tools.golangci-lint."platforms.macos-x64"] checksum = "sha256:c900d4048db75d1edfd550fd11cf6a9b3008e7caa8e119fcddbc700412d63e60" url = "https://github.com/golangci/golangci-lint/releases/download/v2.11.4/golangci-lint-2.11.4-darwin-amd64.tar.gz" +provenance = "github-attestations" [tools.golangci-lint."platforms.windows-x64"] checksum = "sha256:4932cfca5e75bf60fe1c576edf459e5e809e6644664a068185d64b84af3fad9e" url = "https://github.com/golangci/golangci-lint/releases/download/v2.11.4/golangci-lint-2.11.4-windows-amd64.zip" +provenance = "github-attestations" [[tools.golangci-lint-langserver]] version = "0.0.12" @@ -188,37 +234,65 @@ backend = "aqua:goreleaser/goreleaser" [tools.goreleaser."platforms.linux-arm64"] checksum = "sha256:5db66761a98f6693161e49e1a95d28d2673a892ba60cb4a5e16736cafd41c4c9" url = "https://github.com/goreleaser/goreleaser/releases/download/v2.15.2/goreleaser_Linux_arm64.tar.gz" -provenance = "cosign" +provenance = "github-attestations" [tools.goreleaser."platforms.linux-arm64-musl"] checksum = "sha256:5db66761a98f6693161e49e1a95d28d2673a892ba60cb4a5e16736cafd41c4c9" url = "https://github.com/goreleaser/goreleaser/releases/download/v2.15.2/goreleaser_Linux_arm64.tar.gz" -provenance = "cosign" +provenance = "github-attestations" [tools.goreleaser."platforms.linux-x64"] checksum = "sha256:0ebdbf0353aba566b969dde746cc4e4806f96c27aa2f3971b229a9df7611fedc" url = "https://github.com/goreleaser/goreleaser/releases/download/v2.15.2/goreleaser_Linux_x86_64.tar.gz" -provenance = "cosign" +provenance = "github-attestations" [tools.goreleaser."platforms.linux-x64-musl"] checksum = "sha256:0ebdbf0353aba566b969dde746cc4e4806f96c27aa2f3971b229a9df7611fedc" url = "https://github.com/goreleaser/goreleaser/releases/download/v2.15.2/goreleaser_Linux_x86_64.tar.gz" -provenance = "cosign" +provenance = "github-attestations" [tools.goreleaser."platforms.macos-arm64"] checksum = "sha256:0e6bd67688ac949780bf1166813a91f89856898ef4c40d7d46c2c74ebaa4b9ee" url = "https://github.com/goreleaser/goreleaser/releases/download/v2.15.2/goreleaser_Darwin_all.tar.gz" -provenance = "cosign" +provenance = "github-attestations" [tools.goreleaser."platforms.macos-x64"] checksum = "sha256:0e6bd67688ac949780bf1166813a91f89856898ef4c40d7d46c2c74ebaa4b9ee" url = "https://github.com/goreleaser/goreleaser/releases/download/v2.15.2/goreleaser_Darwin_all.tar.gz" -provenance = "cosign" +provenance = "github-attestations" [tools.goreleaser."platforms.windows-x64"] checksum = "sha256:7459832946dbe122c144f8d7f87484d8572ca005b779310aa6bb03346e8de17a" url = "https://github.com/goreleaser/goreleaser/releases/download/v2.15.2/goreleaser_Windows_x86_64.zip" -provenance = "cosign" +provenance = "github-attestations" + +[[tools.hk]] +version = "1.42.0" +backend = "aqua:jdx/hk" + +[tools.hk."platforms.linux-arm64"] +checksum = "sha256:291ed6215703fc3aa6a9fcbb96a72b88751c50888a00a6a73140ae0fbc3eef70" +url = "https://github.com/jdx/hk/releases/download/v1.42.0/hk-aarch64-unknown-linux-gnu.tar.gz" + +[tools.hk."platforms.linux-arm64-musl"] +checksum = "sha256:291ed6215703fc3aa6a9fcbb96a72b88751c50888a00a6a73140ae0fbc3eef70" +url = "https://github.com/jdx/hk/releases/download/v1.42.0/hk-aarch64-unknown-linux-gnu.tar.gz" + +[tools.hk."platforms.linux-x64"] +checksum = "sha256:a4f8898a83c1521c3e184b8af613ddf8d121df21a4026c679b18b54e8b5953db" +url = "https://github.com/jdx/hk/releases/download/v1.42.0/hk-x86_64-unknown-linux-gnu.tar.gz" + +[tools.hk."platforms.linux-x64-musl"] +checksum = "sha256:a4f8898a83c1521c3e184b8af613ddf8d121df21a4026c679b18b54e8b5953db" +url = "https://github.com/jdx/hk/releases/download/v1.42.0/hk-x86_64-unknown-linux-gnu.tar.gz" + +[tools.hk."platforms.macos-arm64"] +checksum = "sha256:29c4d4aabda87ed8e0a3bcd97cffe288a6932f22ae0a49d77f8a1bb9430afdbe" +url = "https://github.com/jdx/hk/releases/download/v1.42.0/hk-aarch64-apple-darwin.tar.gz" + +[tools.hk."platforms.windows-x64"] +checksum = "sha256:9706dab06f3ed468bb1247ce540dad677acea7bc9a023e8cdbdc5f79b2e4015a" +url = "https://github.com/jdx/hk/releases/download/v1.42.0/hk-x86_64-pc-windows-msvc.zip" [[tools.nfpm]] version = "2.46.0" @@ -270,27 +344,137 @@ backend = "core:python" [tools.python."platforms.linux-arm64"] checksum = "sha256:c84d61ae07e3b255f8bac6a28147bd373c3c1862d1d5598a9543a5b103fcb595" url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260408/cpython-3.14.4+20260408-aarch64-unknown-linux-gnu-install_only_stripped.tar.gz" +provenance = "github-attestations" [tools.python."platforms.linux-arm64-musl"] checksum = "sha256:c84d61ae07e3b255f8bac6a28147bd373c3c1862d1d5598a9543a5b103fcb595" url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260408/cpython-3.14.4+20260408-aarch64-unknown-linux-gnu-install_only_stripped.tar.gz" +provenance = "github-attestations" [tools.python."platforms.linux-x64"] -checksum = "sha256:afbbab0107da1835089ed3bec8e11c742bde064d568729cd64856b0823b42217" -url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260408/cpython-3.14.4+20260408-x86_64_v3-unknown-linux-gnu-install_only_stripped.tar.gz" +checksum = "sha256:c838ac128a6e9c944b30301880472349eca8cd1abc79fb0d359ac2a358569389" +url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260408/cpython-3.14.4+20260408-x86_64-unknown-linux-gnu-install_only_stripped.tar.gz" +provenance = "github-attestations" [tools.python."platforms.linux-x64-musl"] checksum = "sha256:c838ac128a6e9c944b30301880472349eca8cd1abc79fb0d359ac2a358569389" url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260408/cpython-3.14.4+20260408-x86_64-unknown-linux-gnu-install_only_stripped.tar.gz" +provenance = "github-attestations" [tools.python."platforms.macos-arm64"] checksum = "sha256:f1ce5d79bceecbed25a37b611d6dae147b27857dda8181e3a5e29e73dd1c57c3" url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260408/cpython-3.14.4+20260408-aarch64-apple-darwin-install_only_stripped.tar.gz" +provenance = "github-attestations" [tools.python."platforms.macos-x64"] checksum = "sha256:1c9615f872058332b74b2be1b248078c636b6f4b116eed3e17f50eb7efe1a989" url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260408/cpython-3.14.4+20260408-x86_64-apple-darwin-install_only_stripped.tar.gz" +provenance = "github-attestations" [tools.python."platforms.windows-x64"] checksum = "sha256:472f4f0d91429661db1b28a72e36adc593b6bd5d19db222d7faca635b3005313" url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260408/cpython-3.14.4+20260408-x86_64-pc-windows-msvc-install_only_stripped.tar.gz" +provenance = "github-attestations" + +[[tools.ruff]] +version = "0.15.9" +backend = "aqua:astral-sh/ruff" + +[tools.ruff."platforms.linux-arm64"] +checksum = "sha256:e017dd0c1fd7475aaddc49bde8cddcee3c27d42f6ce139a96df0c1022e06d85b" +url = "https://github.com/astral-sh/ruff/releases/download/0.15.9/ruff-aarch64-unknown-linux-musl.tar.gz" +provenance = "github-attestations" + +[tools.ruff."platforms.linux-arm64-musl"] +checksum = "sha256:e017dd0c1fd7475aaddc49bde8cddcee3c27d42f6ce139a96df0c1022e06d85b" +url = "https://github.com/astral-sh/ruff/releases/download/0.15.9/ruff-aarch64-unknown-linux-musl.tar.gz" +provenance = "github-attestations" + +[tools.ruff."platforms.linux-x64"] +checksum = "sha256:e30e6e50dbf925b42335f28e2fa296d404294f294159b314dca47b88317fc477" +url = "https://github.com/astral-sh/ruff/releases/download/0.15.9/ruff-x86_64-unknown-linux-musl.tar.gz" +provenance = "github-attestations" + +[tools.ruff."platforms.linux-x64-musl"] +checksum = "sha256:e30e6e50dbf925b42335f28e2fa296d404294f294159b314dca47b88317fc477" +url = "https://github.com/astral-sh/ruff/releases/download/0.15.9/ruff-x86_64-unknown-linux-musl.tar.gz" +provenance = "github-attestations" + +[tools.ruff."platforms.macos-arm64"] +checksum = "sha256:013d878f17c625550e4a6b19235c22fc229639f66f563bb72cb2c896aeca11e8" +url = "https://github.com/astral-sh/ruff/releases/download/0.15.9/ruff-aarch64-apple-darwin.tar.gz" +provenance = "github-attestations" + +[tools.ruff."platforms.macos-x64"] +checksum = "sha256:7e0fe9daba25848f85cb3d43e47ecd7d23f14e92e8799f92c1bcd8319a4ce4f8" +url = "https://github.com/astral-sh/ruff/releases/download/0.15.9/ruff-x86_64-apple-darwin.tar.gz" +provenance = "github-attestations" + +[tools.ruff."platforms.windows-x64"] +checksum = "sha256:e38fddd19805bc8f7329003c2abdaf49d8ca9e5bc0c6702e8472e16f127bcd44" +url = "https://github.com/astral-sh/ruff/releases/download/0.15.9/ruff-x86_64-pc-windows-msvc.zip" +provenance = "github-attestations" + +[[tools.shellcheck]] +version = "0.11.0" +backend = "aqua:koalaman/shellcheck" + +[tools.shellcheck."platforms.linux-arm64"] +checksum = "sha256:12b331c1d2db6b9eb13cfca64306b1b157a86eb69db83023e261eaa7e7c14588" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.linux.aarch64.tar.xz" + +[tools.shellcheck."platforms.linux-arm64-musl"] +checksum = "sha256:12b331c1d2db6b9eb13cfca64306b1b157a86eb69db83023e261eaa7e7c14588" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.linux.aarch64.tar.xz" + +[tools.shellcheck."platforms.linux-x64"] +checksum = "sha256:8c3be12b05d5c177a04c29e3c78ce89ac86f1595681cab149b65b97c4e227198" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.linux.x86_64.tar.xz" + +[tools.shellcheck."platforms.linux-x64-musl"] +checksum = "sha256:8c3be12b05d5c177a04c29e3c78ce89ac86f1595681cab149b65b97c4e227198" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.linux.x86_64.tar.xz" + +[tools.shellcheck."platforms.macos-arm64"] +checksum = "sha256:56affdd8de5527894dca6dc3d7e0a99a873b0f004d7aabc30ae407d3f48b0a79" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.darwin.aarch64.tar.xz" + +[tools.shellcheck."platforms.macos-x64"] +checksum = "sha256:3c89db4edcab7cf1c27bff178882e0f6f27f7afdf54e859fa041fca10febe4c6" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.darwin.x86_64.tar.xz" + +[tools.shellcheck."platforms.windows-x64"] +checksum = "sha256:8a4e35ab0b331c85d73567b12f2a444df187f483e5079ceffa6bda1faa2e740e" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.zip" + +[[tools.typos]] +version = "1.43.5" +backend = "aqua:crate-ci/typos" + +[tools.typos."platforms.linux-arm64"] +checksum = "sha256:15f2d2592312babea0eabb783e6879085f7ab3bd643aacf4d8290dd7c14c07d0" +url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5-aarch64-unknown-linux-musl.tar.gz" + +[tools.typos."platforms.linux-arm64-musl"] +checksum = "sha256:15f2d2592312babea0eabb783e6879085f7ab3bd643aacf4d8290dd7c14c07d0" +url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5-aarch64-unknown-linux-musl.tar.gz" + +[tools.typos."platforms.linux-x64"] +checksum = "sha256:7bb0734a80c68a2ef1d4d0e64c46d498a50fbdb0d5efddac44e9804a687fef03" +url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5-x86_64-unknown-linux-musl.tar.gz" + +[tools.typos."platforms.linux-x64-musl"] +checksum = "sha256:7bb0734a80c68a2ef1d4d0e64c46d498a50fbdb0d5efddac44e9804a687fef03" +url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5-x86_64-unknown-linux-musl.tar.gz" + +[tools.typos."platforms.macos-arm64"] +checksum = "sha256:0c3fbef95090b0cd6d269a0d4a7ff4d665d5bd2b579179c6b856f7617b1ffc70" +url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5-aarch64-apple-darwin.tar.gz" + +[tools.typos."platforms.macos-x64"] +checksum = "sha256:f675f59c17287923c59b61d63c59092821d32ac35d66bd5ad9c666ad5a702531" +url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5-x86_64-apple-darwin.tar.gz" + +[tools.typos."platforms.windows-x64"] +checksum = "sha256:33bcd71d132fc97c791581996453f0438d985dcec2a0eeedc1107a450bcb42c8" +url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5-x86_64-pc-windows-msvc.zip" diff --git a/mise.toml b/mise.toml index 12adc54..3cafb35 100644 --- a/mise.toml +++ b/mise.toml @@ -1,13 +1,21 @@ [tools] +"actionlint" = "latest" "github:caarlos0/svu" = "latest" go = "latest" +hk = "1.42.0" python = "3" golangci-lint = "latest" golangci-lint-langserver = "latest" goreleaser = "latest" nfpm = "latest" +ruff = "0.15.9" "pipx:hatchling" = "latest" "github:CycloneDX/cyclonedx-gomod" = "latest" +shellcheck = "latest" +typos = "latest" + +[env] +HK_PKL_BACKEND = "pklr" [tasks.format] description = "Format all Go code" @@ -51,6 +59,10 @@ run = "golangci-lint run" dir = "{{cwd}}/box" depends = ["generate:box"] +[tasks."lint:hk"] +description = "Run project level linters" +run = "hk check --all" + [tasks."test:boxer"] description = "Run tests in boxer/" run = "go test -v ./..." @@ -73,7 +85,7 @@ depends = ["fmt-check:box", "lint:box", "test:box"] [tasks.ci] description = "Run all CI checks" -depends = ["ci:boxer", "ci:box"] +depends = ["lint:hk", "ci:boxer", "ci:box"] [tasks.e2e] description = "Run end-to-end tests (build, cross-compile, run)" From f4d5b9a8fdcce1a5b5d1f01001225caaae4af502 Mon Sep 17 00:00:00 2001 From: Vincent MEURISSE Date: Tue, 14 Apr 2026 07:46:55 +0200 Subject: [PATCH 2/2] chore: add zizmor linter --- .github/dependabot.yml | 2 ++ .github/workflows/ci.yml | 16 ++++++++++---- .github/workflows/release.yml | 38 +++++++++++++++++++++------------- hk.pkl | 1 + mise.lock | 39 +++++++++++++++++++++++++++++++++++ mise.toml | 1 + 6 files changed, 79 insertions(+), 18 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index cd88554..8a781f1 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,3 +9,5 @@ updates: directory: "/" # Location of package manifests schedule: interval: "weekly" + cooldown: + default-days: 7 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8096c19..82ca744 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -9,6 +9,10 @@ on: permissions: contents: read +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + jobs: ci: name: Format, Lint, Test (${{ matrix.os }} / ${{ matrix.arch }}) @@ -37,10 +41,12 @@ jobs: runs_on: macos-latest steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 + with: + persist-credentials: false - name: Setup mise - uses: jdx/mise-action@v3 + uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3 - name: Run CI run: mise run ci @@ -72,10 +78,12 @@ jobs: runs_on: macos-latest steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 + with: + persist-credentials: false - name: Setup mise - uses: jdx/mise-action@v3 + uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3 - name: Run end-to-end tests run: mise run e2e diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a562ffa..93c9555 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -21,6 +21,13 @@ on: type: boolean default: true +# Default to empty. Set at job level below +permissions: {} + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false # Don't stop in the middle of a release + jobs: release: name: Build and Release @@ -32,18 +39,21 @@ jobs: steps: # Clone - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 with: - fetch-depth: 0 # Required for tag computation and goreleaser changelog + fetch-depth: 0 # Required for tag computation and goreleaser changelog + persist-credentials: true # Needed to push tags - name: Setup mise - uses: jdx/mise-action@v3 + uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3 + with: + cache: false # Python is needed for GoReleaser post-build hooks that create Python wheels - name: Set up Python - uses: actions/setup-python@v5 + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 with: - python-version: '3.13' + python-version: "3.13" # Dependencies used for wheel builds - name: Install Python build tools @@ -63,17 +73,17 @@ jobs: # GoReleaser builds binaries, creates GitHub release, and runs post-build hooks - name: Run GoReleaser - uses: goreleaser/goreleaser-action@v6 + uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6 with: distribution: goreleaser - version: '~> v2' + version: "~> v2" args: release --clean env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Upload wheels as artifacts for publishing jobs - name: Upload wheels - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: wheels path: wheels/*.whl @@ -103,16 +113,16 @@ jobs: name: testpypi url: https://test.pypi.org/p/uvbox permissions: - id-token: write + id-token: write # Required for trusted publishing on PyPI steps: - name: Download wheels - uses: actions/download-artifact@v4 + uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 with: name: wheels path: wheels/ - name: Publish to Test PyPI - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # release/v1 with: repository-url: https://test.pypi.org/legacy/ packages-dir: wheels/ @@ -128,16 +138,16 @@ jobs: name: pypi url: https://pypi.org/p/uvbox permissions: - id-token: write + id-token: write # Required for trusted publishing on PyPI steps: - name: Download wheels - uses: actions/download-artifact@v4 + uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 with: name: wheels path: wheels/ - name: Publish to PyPI - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # release/v1 with: packages-dir: wheels/ skip-existing: true diff --git a/hk.pkl b/hk.pkl index dc009cd..91c8298 100644 --- a/hk.pkl +++ b/hk.pkl @@ -51,6 +51,7 @@ local python_linters = new Mapping { // --------------------------------------------------------------------------- local infra_linters = new Mapping { ["actionlint"] = Builtins.actionlint + ["zizmor"] = Builtins.zizmor } // --------------------------------------------------------------------------- diff --git a/mise.lock b/mise.lock index 5b4bda1..5bac8e0 100644 --- a/mise.lock +++ b/mise.lock @@ -478,3 +478,42 @@ url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5 [tools.typos."platforms.windows-x64"] checksum = "sha256:33bcd71d132fc97c791581996453f0438d985dcec2a0eeedc1107a450bcb42c8" url = "https://github.com/crate-ci/typos/releases/download/v1.43.5/typos-v1.43.5-x86_64-pc-windows-msvc.zip" + +[[tools.zizmor]] +version = "1.23.1" +backend = "aqua:zizmorcore/zizmor" + +[tools.zizmor."platforms.linux-arm64"] +checksum = "sha256:3725d7cd7102e4d70827186389f7d5930b6878232930d0a3eb058d7e5b47e658" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.23.1/zizmor-aarch64-unknown-linux-gnu.tar.gz" +provenance = "github-attestations" + +[tools.zizmor."platforms.linux-arm64-musl"] +checksum = "sha256:3725d7cd7102e4d70827186389f7d5930b6878232930d0a3eb058d7e5b47e658" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.23.1/zizmor-aarch64-unknown-linux-gnu.tar.gz" +provenance = "github-attestations" + +[tools.zizmor."platforms.linux-x64"] +checksum = "sha256:67a8df0a14352dd81882e14876653d097b99b0f4f6b6fe798edc0320cff27aff" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.23.1/zizmor-x86_64-unknown-linux-gnu.tar.gz" +provenance = "github-attestations" + +[tools.zizmor."platforms.linux-x64-musl"] +checksum = "sha256:67a8df0a14352dd81882e14876653d097b99b0f4f6b6fe798edc0320cff27aff" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.23.1/zizmor-x86_64-unknown-linux-gnu.tar.gz" +provenance = "github-attestations" + +[tools.zizmor."platforms.macos-arm64"] +checksum = "sha256:2632561b974c69f952258c1ab4b7432d5c7f92e555704155c3ac28a2910bd717" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.23.1/zizmor-aarch64-apple-darwin.tar.gz" +provenance = "github-attestations" + +[tools.zizmor."platforms.macos-x64"] +checksum = "sha256:89d5ed42081dd9d0433a10b7545fac42b35f1f030885c278b9712b32c66f2597" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.23.1/zizmor-x86_64-apple-darwin.tar.gz" +provenance = "github-attestations" + +[tools.zizmor."platforms.windows-x64"] +checksum = "sha256:33c2293ff02834720dd7cd8b47348aafb2e95a19bdc993c0ecaca9c804ade92a" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.23.1/zizmor-x86_64-pc-windows-msvc.zip" +provenance = "github-attestations" diff --git a/mise.toml b/mise.toml index 3cafb35..971725a 100644 --- a/mise.toml +++ b/mise.toml @@ -13,6 +13,7 @@ ruff = "0.15.9" "github:CycloneDX/cyclonedx-gomod" = "latest" shellcheck = "latest" typos = "latest" +zizmor = "latest" [env] HK_PKL_BACKEND = "pklr"