workflows/scheduled: fix template-injection zizmor warnings#195308
Merged
Conversation
SMillerDev
approved these changes
Dec 15, 2024
Bo98
reviewed
Dec 15, 2024
This updates `workflows/scheduled.yml` to use environment variables to address `template-injection` warnings from `zizmor`. This borrows the general approach from similar fixes in the Homebrew/actions and Homebrew/homebrew-test-bot repositories. This also updates `github.*` references with default environment variables provided by GitHub (where available).
4802e20 to
ad2a8d6
Compare
Bo98
approved these changes
Dec 15, 2024
SMillerDev
approved these changes
Dec 15, 2024
bevanjkay
approved these changes
Dec 15, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Important: Do not tick a checkbox if you haven’t performed its action. Honesty is indispensable for a smooth review process.
In the following questions
<cask>is the token of the cask you're submitting.After making any changes to a cask, existing or new, verify:
brew audit --cask --online <cask>is error-free.brew style --fix <cask>reports no offenses.Additionally, if adding a new cask:
brew audit --cask --new <cask>worked successfully.HOMEBREW_NO_INSTALL_FROM_API=1 brew install --cask <cask>worked successfully.brew uninstall --cask <cask>worked successfully.This updates
workflows/scheduled.ymlto use environment variables to addresstemplate-injectionwarnings fromzizmor. This borrows the general approach from similar fixes in the Homebrew/actions and Homebrew/homebrew-test-bot repositories.I'm not very knowledgeable about GitHub Actions, so I've set this as a draft until more knowledgeable maintainers have had a chance to check my work and identify any issues.