Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update pypa/gh-action-pypi-publish digest to fb9fc6a #63

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 18, 2023

Mend Renovate

This PR contains the following updates:

Package Type Update Change
pypa/gh-action-pypi-publish action digest 27b3170 -> fb9fc6a

Configuration

πŸ“… Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

β™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 2f6f737 Update pypa/gh-action-pypi-publish digest to c12cc61 Dec 20, 2023
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from f7fbc5a to 65baffd Compare December 20, 2023 13:01
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to c12cc61 chore(deps): update pypa/gh-action-pypi-publish digest to c12cc61 Jan 9, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 65baffd to 70d17c5 Compare January 9, 2024 20:46
@renovate renovate bot changed the title chore(deps): update pypa/gh-action-pypi-publish digest to c12cc61 Update pypa/gh-action-pypi-publish digest to c12cc61 Jan 9, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 2 times, most recently from 423ae5d to f3b2eb3 Compare January 16, 2024 08:16
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to c12cc61 Update pypa/gh-action-pypi-publish digest to e82f99a Feb 5, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from f3b2eb3 to 50c88b1 Compare February 5, 2024 17:14
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to e82f99a Update pypa/gh-action-pypi-publish digest to 3f824c7 Feb 5, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 50c88b1 to e868838 Compare February 5, 2024 19:25
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 3f824c7 Update pypa/gh-action-pypi-publish digest to 0580fcb Feb 8, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from e868838 to e517cbb Compare February 8, 2024 04:12
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 2 times, most recently from ce48a02 to c7a1936 Compare February 17, 2024 05:09
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 0580fcb Update pypa/gh-action-pypi-publish digest to 72a79c8 Feb 17, 2024
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 72a79c8 Update pypa/gh-action-pypi-publish digest to 24c5d5c Feb 22, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from c7a1936 to a2e6b2e Compare February 22, 2024 03:18
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 24c5d5c Update pypa/gh-action-pypi-publish digest to edfa8f3 Feb 24, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from a2e6b2e to 203a8fd Compare February 24, 2024 22:32
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to edfa8f3 Update pypa/gh-action-pypi-publish digest to e53eb8b Feb 27, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 203a8fd to 0d062bf Compare February 27, 2024 06:49
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to e53eb8b Update pypa/gh-action-pypi-publish digest to aec4e82 Mar 6, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 0d062bf to a4bbd06 Compare March 6, 2024 19:00
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to aec4e82 Update pypa/gh-action-pypi-publish digest to 741947b Mar 7, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from a4bbd06 to 593c7a3 Compare March 7, 2024 23:06
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 741947b Update pypa/gh-action-pypi-publish digest to 81e9d93 Mar 8, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 593c7a3 to 67a055e Compare March 8, 2024 00:11
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 81e9d93 Update pypa/gh-action-pypi-publish digest to 3fbcf7c Apr 12, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 67a055e to 720f261 Compare April 12, 2024 13:54
Copy link

dryrunsecurity bot commented Apr 12, 2024

Hi there πŸ‘‹, @DryRunSecurity here, below is a summary of our analysis and findings.

DryRun Security Status Findings
Server-Side Request Forgery Analyzer βœ… 0 findings
Configured Codepaths Analyzer βœ… 0 findings
IDOR Analyzer βœ… 0 findings
SQL Injection Analyzer βœ… 0 findings
Secrets Analyzer βœ… 0 findings
Authn/Authz Analyzer βœ… 0 findings
Sensitive Files Analyzer βœ… 0 findings

Note

🟒 Risk threshold not exceeded.

Change Summary (click to expand)

The following is a summary of changes in this pull request made by me, your security buddy πŸ€–. Note that this summary is auto-generated and not meant to be a definitive list of security issues but rather a helpful summary from a security perspective.

Summary:

The provided code change is related to a GitHub Actions workflow for publishing a Python package to the PyPI (Python Package Index) repository. The main change is an update to the version of the pypa/gh-action-pypi-publish GitHub Action used in the workflow.

From an application security perspective, the changes in this pull request do not appear to introduce any major security concerns. However, it's important to review the dependency update, ensure proper secrets management, and verify the workflow permissions to maintain the overall security of the application.

Files Changed:

  • .github/workflows/python-publish.yml: This file is a GitHub Actions workflow configuration that is responsible for publishing a Python package to the PyPI repository. The main change in this pull request is an update to the version of the pypa/gh-action-pypi-publish GitHub Action used in the workflow. While this change does not directly introduce any security vulnerabilities, it's important to review the changes in the new version of the GitHub Action to ensure there are no known security-related issues.

Additionally, the workflow uses a secret PYPI_API_TOKEN to authenticate with PyPI for publishing the package, and it's crucial to ensure that this secret is properly managed and protected. The workflow also has the contents: read permission, which is the minimum required permission for the checkout action, but it's a good practice to review the permissions granted to the workflow and ensure that they are the minimum necessary for the task at hand.

Powered by DryRun Security

@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 3fbcf7c Update pypa/gh-action-pypi-publish digest to 699cd61 May 16, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 720f261 to 431396c Compare May 16, 2024 21:59
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 699cd61 Update pypa/gh-action-pypi-publish digest to 2734d07 May 29, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 431396c to ddd3c6a Compare May 29, 2024 15:51
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 2734d07 Update pypa/gh-action-pypi-publish digest to 87b624f May 29, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from ddd3c6a to 3b50f01 Compare May 29, 2024 22:10
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to 87b624f Update pypa/gh-action-pypi-publish digest to ec4db0b Jun 16, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 3b50f01 to 2aeb7f7 Compare June 16, 2024 19:11
@renovate renovate bot changed the title Update pypa/gh-action-pypi-publish digest to ec4db0b Update pypa/gh-action-pypi-publish digest to fb9fc6a Jun 27, 2024
@renovate renovate bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from 2aeb7f7 to 5684f31 Compare June 27, 2024 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant