diff --git a/.github/scripts/write_release_notes.py b/.github/scripts/write_release_notes.py index af55f6c..987e6bf 100644 --- a/.github/scripts/write_release_notes.py +++ b/.github/scripts/write_release_notes.py @@ -15,18 +15,7 @@ def gh(*args: str) -> str: def latest_tag() -> str: - return gh( - "release", - "list", - "--repo", - os.environ["GITHUB_REPOSITORY"], - "-L", - "1", - "--json", - "tagName", - "-q", - ".[0].tagName", - ) + return gh("release", "list", "-L", "1", "--json", "tagName", "-q", ".[0].tagName") def merged_prs() -> list[dict]: @@ -36,8 +25,6 @@ def merged_prs() -> list[dict]: prs = gh( "pr", "list", - "--repo", - repo, "--state", "merged", "--base", diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 8adb0d3..dc6c0b8 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -28,6 +28,8 @@ jobs: uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Check version id: check + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | set -euo pipefail version="$(uvx --from "$PWD" gimmegit --version)" @@ -40,8 +42,6 @@ jobs: fi fi echo "release=$release" >> "$GITHUB_OUTPUT" - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} wait-checks: runs-on: ubuntu-latest @@ -53,21 +53,23 @@ jobs: outputs: release: ${{ steps.wait.outputs.release }} steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Wait for checks id: wait env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - REPO: ${{ github.repository }} run: | set -euo pipefail sha="${{ github.sha }}" release=false # Wait for all other workflow runs on this SHA to complete. - other_runs="$(gh run list --repo "$REPO" --branch main --limit 50 --json databaseId,headSha --jq ".[] | select(.headSha == \"${sha}\") | .databaseId")" + other_runs="$(gh run list --branch main --limit 50 --json databaseId,headSha --jq ".[] | select(.headSha == \"${sha}\") | .databaseId")" other_runs="$(echo "$other_runs" | grep -v "${{ github.run_id }}" || true)" all_passed=true for run in $other_runs; do - if ! gh run watch "$run" --repo "$REPO" --exit-status >/dev/null 2>&1; then + if ! gh run watch "$run" --exit-status >/dev/null 2>&1; then all_passed=false fi done @@ -84,6 +86,9 @@ jobs: contents: write pull-requests: read steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Install uv uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Create draft release @@ -91,8 +96,7 @@ jobs: env: VERSION: ${{ needs.check-version.outputs.version }} GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - REPO: ${{ github.repository }} run: | set -euo pipefail notes="$(uv run --script .github/scripts/write_release_notes.py "$VERSION")" - gh release create "$VERSION" --repo "$REPO" --draft --target main --notes "$notes" + gh release create "$VERSION" --draft --target main --notes "$notes" diff --git a/.github/workflows/zizmor.yaml b/.github/workflows/zizmor.yaml index cfdd789..fd47d3a 100644 --- a/.github/workflows/zizmor.yaml +++ b/.github/workflows/zizmor.yaml @@ -21,9 +21,9 @@ jobs: - name: Install uv uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Run zizmor - run: uv run zizmor --format=sarif . > workflows.sarif env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Avoid rate limits for zizmor's "online" checks. + run: uv run zizmor --format=sarif . > workflows.sarif - name: Upload SARIF file uses: github/codeql-action/upload-sarif@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 with: