From 432d5a1a94cb9a0650ba09c00e54cf3723bb1e67 Mon Sep 17 00:00:00 2001 From: Salman Muin Kayser Chishti <13schishti@gmail.com> Date: Wed, 17 Dec 2025 11:11:54 +0000 Subject: [PATCH] Fix pypa/gh-action-pypi-publish version reference The previous change incorrectly used @v1 which doesn't exist. Pin to release/v1.13 SHA for security best practices. Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com> --- .github/workflows/publish.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index b894bc2..38caa05 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -29,4 +29,4 @@ jobs: - name: Build package run: uv build - name: Publish to PyPI - uses: pypa/gh-action-pypi-publish@v1 + uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # release/v1.13 \ No newline at end of file