From 8ea83d3356d92318c993cb6ee56b1ca1ac7552c6 Mon Sep 17 00:00:00 2001 From: Facundo Tuesca Date: Fri, 21 Nov 2025 18:53:59 +0100 Subject: [PATCH 1/2] Update CHANGELOG Signed-off-by: Facundo Tuesca --- CHANGELOG.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index bcd94b5..61de91a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +### Changed + +- The minimum Python version required is now `3.10` + ## [0.0.28] ### Changed From ed61fddeb26a7c431accf86ce5c8b85422335ebd Mon Sep 17 00:00:00 2001 From: Facundo Tuesca Date: Fri, 21 Nov 2025 18:54:10 +0100 Subject: [PATCH 2/2] Add zizmor to CI workflows Signed-off-by: Facundo Tuesca --- .github/workflows/zizmor.yml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..088cd38 --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,26 @@ +name: GitHub Actions Security Analysis with zizmor 🌈 + +on: + push: + branches: ["main"] + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + name: Run zizmor 🌈 + runs-on: ubuntu-latest + permissions: + security-events: write + contents: read # only needed for private repos + actions: read # only needed for private repos + steps: + - name: Checkout repository + uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0 + with: + persist-credentials: false + + - name: Run zizmor 🌈 + uses: zizmorcore/zizmor-action@e673c3917a1aef3c65c972347ed84ccd013ecda4 # v0.2.0