Skip to content

Hash-pin action usages, minimize CI/CD permissions - #309

Merged
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci
Apr 13, 2026
Merged

Hash-pin action usages, minimize CI/CD permissions#309
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci

Conversation

@woodruffw

Copy link
Copy Markdown
Contributor

Hello! This addresses some findings from zizmor 🙂

TL;DR is that I've hash-pinned all actions to make them more hermetic (making it harder for an attacker who compromises an action to push code directly to you via a mutable tag or branch). I've also added a Dependabot config that'll keep actions up-to-date, with a cooldown period that'll ensure that any action changes have at least a week to bake/receive security scrutiny before they're proposed for your inclusion. Separately, I've made the permissions on your CI/CD as minimal as possible and removed a very minor source of on-disk credential persistence via actions/checkout.

With these changes, the only remaining default zizmor finding is this:

warning[secrets-outside-env]: secrets referenced without a dedicated environment
--> ./.github/workflows/build.yml:82:20
|
18 | build:
| ----- this job
...
82 | token: ${{ secrets.CODECOV_ORG_TOKEN }}
| ^^^^^^^^^^^^^^^^^^^^^^^^^ secret is accessed outside of a dedicated environment
|
= note: audit confidence → High
3 findings (2 suppressed): 0 informational, 0 low, 1 medium, 0 high

...which is pretty minor, but could be resolved by a maintainer by moving that credential into a dedicated deployment environment.

Separately, I have not included a CI integration for zizmor in this PR. But if you're interested in one LMK and I'd be happy to do a follow up PR for it!

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@zooba

Copy link
Copy Markdown
Member

Thanks. We'll see how dependabot goes, I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down. Is there a way to make sure it's constrained to only complain about important stuff (such as pipelines) and not (e.g.) test data?

@woodruffw

Copy link
Copy Markdown
ContributorAuthor

I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down

Same 😅 -- what I've done here is configure Dependabot to hopefully be a bit less noisy than the defaults: the current config will only run update checks once a week, and will batch all updates into a single PR. I've also only enabled the github-actions updater, so Dependabot shouldn't nag you with Python dep bumps or anything else.

(It's very easy to further ratchet that down as well, e.g. to only do updates every month or even every quarter. Whatever works for you, I'm happy to amend to!)

@zooba

Copy link
Copy Markdown
Member

Batching all updates is finally here ❤️

Let's do it. I'm in the middle of pinning other build-time dependencies, but I wouldn't have got these, so the PR is well timed.

@zooba
zooba merged commit 3efddd1 into python:mainApr 13, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@woodruffw@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Hash-pin action usages, minimize CI/CD permissions by woodruffw · Pull Request #309 · python/pymanager · GitHub
Skip to content

Hash-pin action usages, minimize CI/CD permissions - #309

Merged
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci
Apr 13, 2026
Merged

Hash-pin action usages, minimize CI/CD permissions#309
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci

Conversation

@woodruffw

Copy link
Copy Markdown
Contributor

Hello! This addresses some findings from zizmor 🙂

TL;DR is that I've hash-pinned all actions to make them more hermetic (making it harder for an attacker who compromises an action to push code directly to you via a mutable tag or branch). I've also added a Dependabot config that'll keep actions up-to-date, with a cooldown period that'll ensure that any action changes have at least a week to bake/receive security scrutiny before they're proposed for your inclusion. Separately, I've made the permissions on your CI/CD as minimal as possible and removed a very minor source of on-disk credential persistence via actions/checkout.

With these changes, the only remaining default zizmor finding is this:

warning[secrets-outside-env]: secrets referenced without a dedicated environment
--> ./.github/workflows/build.yml:82:20
|
18 | build:
| ----- this job
...
82 | token: ${{ secrets.CODECOV_ORG_TOKEN }}
| ^^^^^^^^^^^^^^^^^^^^^^^^^ secret is accessed outside of a dedicated environment
|
= note: audit confidence → High
3 findings (2 suppressed): 0 informational, 0 low, 1 medium, 0 high

...which is pretty minor, but could be resolved by a maintainer by moving that credential into a dedicated deployment environment.

Separately, I have not included a CI integration for zizmor in this PR. But if you're interested in one LMK and I'd be happy to do a follow up PR for it!

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@zooba

Copy link
Copy Markdown
Member

Thanks. We'll see how dependabot goes, I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down. Is there a way to make sure it's constrained to only complain about important stuff (such as pipelines) and not (e.g.) test data?

@woodruffw

Copy link
Copy Markdown
ContributorAuthor

I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down

Same 😅 -- what I've done here is configure Dependabot to hopefully be a bit less noisy than the defaults: the current config will only run update checks once a week, and will batch all updates into a single PR. I've also only enabled the github-actions updater, so Dependabot shouldn't nag you with Python dep bumps or anything else.

(It's very easy to further ratchet that down as well, e.g. to only do updates every month or even every quarter. Whatever works for you, I'm happy to amend to!)

@zooba

Copy link
Copy Markdown
Member

Batching all updates is finally here ❤️

Let's do it. I'm in the middle of pinning other build-time dependencies, but I wouldn't have got these, so the PR is well timed.

@zooba
zooba merged commit 3efddd1 into python:mainApr 13, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@woodruffw@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Hash-pin action usages, minimize CI/CD permissions by woodruffw · Pull Request #309 · python/pymanager · GitHub
Skip to content

Hash-pin action usages, minimize CI/CD permissions - #309

Merged
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci
Apr 13, 2026
Merged

Hash-pin action usages, minimize CI/CD permissions#309
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci

Conversation

@woodruffw

Copy link
Copy Markdown
Contributor

Hello! This addresses some findings from zizmor 🙂

TL;DR is that I've hash-pinned all actions to make them more hermetic (making it harder for an attacker who compromises an action to push code directly to you via a mutable tag or branch). I've also added a Dependabot config that'll keep actions up-to-date, with a cooldown period that'll ensure that any action changes have at least a week to bake/receive security scrutiny before they're proposed for your inclusion. Separately, I've made the permissions on your CI/CD as minimal as possible and removed a very minor source of on-disk credential persistence via actions/checkout.

With these changes, the only remaining default zizmor finding is this:

warning[secrets-outside-env]: secrets referenced without a dedicated environment
--> ./.github/workflows/build.yml:82:20
|
18 | build:
| ----- this job
...
82 | token: ${{ secrets.CODECOV_ORG_TOKEN }}
| ^^^^^^^^^^^^^^^^^^^^^^^^^ secret is accessed outside of a dedicated environment
|
= note: audit confidence → High
3 findings (2 suppressed): 0 informational, 0 low, 1 medium, 0 high

...which is pretty minor, but could be resolved by a maintainer by moving that credential into a dedicated deployment environment.

Separately, I have not included a CI integration for zizmor in this PR. But if you're interested in one LMK and I'd be happy to do a follow up PR for it!

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@zooba

Copy link
Copy Markdown
Member

Thanks. We'll see how dependabot goes, I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down. Is there a way to make sure it's constrained to only complain about important stuff (such as pipelines) and not (e.g.) test data?

@woodruffw

Copy link
Copy Markdown
ContributorAuthor

I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down

Same 😅 -- what I've done here is configure Dependabot to hopefully be a bit less noisy than the defaults: the current config will only run update checks once a week, and will batch all updates into a single PR. I've also only enabled the github-actions updater, so Dependabot shouldn't nag you with Python dep bumps or anything else.

(It's very easy to further ratchet that down as well, e.g. to only do updates every month or even every quarter. Whatever works for you, I'm happy to amend to!)

@zooba

Copy link
Copy Markdown
Member

Batching all updates is finally here ❤️

Let's do it. I'm in the middle of pinning other build-time dependencies, but I wouldn't have got these, so the PR is well timed.

@zooba
zooba merged commit 3efddd1 into python:mainApr 13, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@woodruffw@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Hash-pin action usages, minimize CI/CD permissions by woodruffw · Pull Request #309 · python/pymanager · GitHub
Skip to content

Hash-pin action usages, minimize CI/CD permissions - #309

Merged
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci
Apr 13, 2026
Merged

Hash-pin action usages, minimize CI/CD permissions#309
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci

Conversation

@woodruffw

Copy link
Copy Markdown
Contributor

Hello! This addresses some findings from zizmor 🙂

TL;DR is that I've hash-pinned all actions to make them more hermetic (making it harder for an attacker who compromises an action to push code directly to you via a mutable tag or branch). I've also added a Dependabot config that'll keep actions up-to-date, with a cooldown period that'll ensure that any action changes have at least a week to bake/receive security scrutiny before they're proposed for your inclusion. Separately, I've made the permissions on your CI/CD as minimal as possible and removed a very minor source of on-disk credential persistence via actions/checkout.

With these changes, the only remaining default zizmor finding is this:

warning[secrets-outside-env]: secrets referenced without a dedicated environment
--> ./.github/workflows/build.yml:82:20
|
18 | build:
| ----- this job
...
82 | token: ${{ secrets.CODECOV_ORG_TOKEN }}
| ^^^^^^^^^^^^^^^^^^^^^^^^^ secret is accessed outside of a dedicated environment
|
= note: audit confidence → High
3 findings (2 suppressed): 0 informational, 0 low, 1 medium, 0 high

...which is pretty minor, but could be resolved by a maintainer by moving that credential into a dedicated deployment environment.

Separately, I have not included a CI integration for zizmor in this PR. But if you're interested in one LMK and I'd be happy to do a follow up PR for it!

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@zooba

Copy link
Copy Markdown
Member

Thanks. We'll see how dependabot goes, I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down. Is there a way to make sure it's constrained to only complain about important stuff (such as pipelines) and not (e.g.) test data?

@woodruffw

Copy link
Copy Markdown
ContributorAuthor

I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down

Same 😅 -- what I've done here is configure Dependabot to hopefully be a bit less noisy than the defaults: the current config will only run update checks once a week, and will batch all updates into a single PR. I've also only enabled the github-actions updater, so Dependabot shouldn't nag you with Python dep bumps or anything else.

(It's very easy to further ratchet that down as well, e.g. to only do updates every month or even every quarter. Whatever works for you, I'm happy to amend to!)

@zooba

Copy link
Copy Markdown
Member

Batching all updates is finally here ❤️

Let's do it. I'm in the middle of pinning other build-time dependencies, but I wouldn't have got these, so the PR is well timed.

@zooba
zooba merged commit 3efddd1 into python:mainApr 13, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@woodruffw@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Hash-pin action usages, minimize CI/CD permissions by woodruffw · Pull Request #309 · python/pymanager · GitHub
Skip to content

Hash-pin action usages, minimize CI/CD permissions - #309

Merged
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci
Apr 13, 2026
Merged

Hash-pin action usages, minimize CI/CD permissions#309
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci

Conversation

@woodruffw

Copy link
Copy Markdown
Contributor

Hello! This addresses some findings from zizmor 🙂

TL;DR is that I've hash-pinned all actions to make them more hermetic (making it harder for an attacker who compromises an action to push code directly to you via a mutable tag or branch). I've also added a Dependabot config that'll keep actions up-to-date, with a cooldown period that'll ensure that any action changes have at least a week to bake/receive security scrutiny before they're proposed for your inclusion. Separately, I've made the permissions on your CI/CD as minimal as possible and removed a very minor source of on-disk credential persistence via actions/checkout.

With these changes, the only remaining default zizmor finding is this:

warning[secrets-outside-env]: secrets referenced without a dedicated environment
--> ./.github/workflows/build.yml:82:20
|
18 | build:
| ----- this job
...
82 | token: ${{ secrets.CODECOV_ORG_TOKEN }}
| ^^^^^^^^^^^^^^^^^^^^^^^^^ secret is accessed outside of a dedicated environment
|
= note: audit confidence → High
3 findings (2 suppressed): 0 informational, 0 low, 1 medium, 0 high

...which is pretty minor, but could be resolved by a maintainer by moving that credential into a dedicated deployment environment.

Separately, I have not included a CI integration for zizmor in this PR. But if you're interested in one LMK and I'd be happy to do a follow up PR for it!

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@zooba

Copy link
Copy Markdown
Member

Thanks. We'll see how dependabot goes, I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down. Is there a way to make sure it's constrained to only complain about important stuff (such as pipelines) and not (e.g.) test data?

@woodruffw

Copy link
Copy Markdown
ContributorAuthor

I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down

Same 😅 -- what I've done here is configure Dependabot to hopefully be a bit less noisy than the defaults: the current config will only run update checks once a week, and will batch all updates into a single PR. I've also only enabled the github-actions updater, so Dependabot shouldn't nag you with Python dep bumps or anything else.

(It's very easy to further ratchet that down as well, e.g. to only do updates every month or even every quarter. Whatever works for you, I'm happy to amend to!)

@zooba

Copy link
Copy Markdown
Member

Batching all updates is finally here ❤️

Let's do it. I'm in the middle of pinning other build-time dependencies, but I wouldn't have got these, so the PR is well timed.

@zooba
zooba merged commit 3efddd1 into python:mainApr 13, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@woodruffw@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Hash-pin action usages, minimize CI/CD permissions by woodruffw · Pull Request #309 · python/pymanager · GitHub
Skip to content

Hash-pin action usages, minimize CI/CD permissions - #309

Merged
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci
Apr 13, 2026
Merged

Hash-pin action usages, minimize CI/CD permissions#309
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci

Conversation

@woodruffw

Copy link
Copy Markdown
Contributor

Hello! This addresses some findings from zizmor 🙂

TL;DR is that I've hash-pinned all actions to make them more hermetic (making it harder for an attacker who compromises an action to push code directly to you via a mutable tag or branch). I've also added a Dependabot config that'll keep actions up-to-date, with a cooldown period that'll ensure that any action changes have at least a week to bake/receive security scrutiny before they're proposed for your inclusion. Separately, I've made the permissions on your CI/CD as minimal as possible and removed a very minor source of on-disk credential persistence via actions/checkout.

With these changes, the only remaining default zizmor finding is this:

warning[secrets-outside-env]: secrets referenced without a dedicated environment
--> ./.github/workflows/build.yml:82:20
|
18 | build:
| ----- this job
...
82 | token: ${{ secrets.CODECOV_ORG_TOKEN }}
| ^^^^^^^^^^^^^^^^^^^^^^^^^ secret is accessed outside of a dedicated environment
|
= note: audit confidence → High
3 findings (2 suppressed): 0 informational, 0 low, 1 medium, 0 high

...which is pretty minor, but could be resolved by a maintainer by moving that credential into a dedicated deployment environment.

Separately, I have not included a CI integration for zizmor in this PR. But if you're interested in one LMK and I'd be happy to do a follow up PR for it!

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@zooba

Copy link
Copy Markdown
Member

Thanks. We'll see how dependabot goes, I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down. Is there a way to make sure it's constrained to only complain about important stuff (such as pipelines) and not (e.g.) test data?

@woodruffw

Copy link
Copy Markdown
ContributorAuthor

I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down

Same 😅 -- what I've done here is configure Dependabot to hopefully be a bit less noisy than the defaults: the current config will only run update checks once a week, and will batch all updates into a single PR. I've also only enabled the github-actions updater, so Dependabot shouldn't nag you with Python dep bumps or anything else.

(It's very easy to further ratchet that down as well, e.g. to only do updates every month or even every quarter. Whatever works for you, I'm happy to amend to!)

@zooba

Copy link
Copy Markdown
Member

Batching all updates is finally here ❤️

Let's do it. I'm in the middle of pinning other build-time dependencies, but I wouldn't have got these, so the PR is well timed.

@zooba
zooba merged commit 3efddd1 into python:mainApr 13, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@woodruffw@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Hash-pin action usages, minimize CI/CD permissions by woodruffw · Pull Request #309 · python/pymanager · GitHub
Skip to content

Hash-pin action usages, minimize CI/CD permissions - #309

Merged
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci
Apr 13, 2026
Merged

Hash-pin action usages, minimize CI/CD permissions#309
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci

Conversation

@woodruffw

Copy link
Copy Markdown
Contributor

Hello! This addresses some findings from zizmor 🙂

TL;DR is that I've hash-pinned all actions to make them more hermetic (making it harder for an attacker who compromises an action to push code directly to you via a mutable tag or branch). I've also added a Dependabot config that'll keep actions up-to-date, with a cooldown period that'll ensure that any action changes have at least a week to bake/receive security scrutiny before they're proposed for your inclusion. Separately, I've made the permissions on your CI/CD as minimal as possible and removed a very minor source of on-disk credential persistence via actions/checkout.

With these changes, the only remaining default zizmor finding is this:

warning[secrets-outside-env]: secrets referenced without a dedicated environment
--> ./.github/workflows/build.yml:82:20
|
18 | build:
| ----- this job
...
82 | token: ${{ secrets.CODECOV_ORG_TOKEN }}
| ^^^^^^^^^^^^^^^^^^^^^^^^^ secret is accessed outside of a dedicated environment
|
= note: audit confidence → High
3 findings (2 suppressed): 0 informational, 0 low, 1 medium, 0 high

...which is pretty minor, but could be resolved by a maintainer by moving that credential into a dedicated deployment environment.

Separately, I have not included a CI integration for zizmor in this PR. But if you're interested in one LMK and I'd be happy to do a follow up PR for it!

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@zooba

Copy link
Copy Markdown
Member

Thanks. We'll see how dependabot goes, I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down. Is there a way to make sure it's constrained to only complain about important stuff (such as pipelines) and not (e.g.) test data?

@woodruffw

Copy link
Copy Markdown
ContributorAuthor

I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down

Same 😅 -- what I've done here is configure Dependabot to hopefully be a bit less noisy than the defaults: the current config will only run update checks once a week, and will batch all updates into a single PR. I've also only enabled the github-actions updater, so Dependabot shouldn't nag you with Python dep bumps or anything else.

(It's very easy to further ratchet that down as well, e.g. to only do updates every month or even every quarter. Whatever works for you, I'm happy to amend to!)

@zooba

Copy link
Copy Markdown
Member

Batching all updates is finally here ❤️

Let's do it. I'm in the middle of pinning other build-time dependencies, but I wouldn't have got these, so the PR is well timed.

@zooba
zooba merged commit 3efddd1 into python:mainApr 13, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@woodruffw@zooba
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Hash-pin action usages, minimize CI/CD permissions by woodruffw · Pull Request #309 · python/pymanager · GitHub
Skip to content

Hash-pin action usages, minimize CI/CD permissions - #309

Merged
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci
Apr 13, 2026
Merged

Hash-pin action usages, minimize CI/CD permissions#309
zooba merged 2 commits into
python:mainfrom
woodruffw-forks:ww/ci

Conversation

@woodruffw

Copy link
Copy Markdown
Contributor

Hello! This addresses some findings from zizmor 🙂

TL;DR is that I've hash-pinned all actions to make them more hermetic (making it harder for an attacker who compromises an action to push code directly to you via a mutable tag or branch). I've also added a Dependabot config that'll keep actions up-to-date, with a cooldown period that'll ensure that any action changes have at least a week to bake/receive security scrutiny before they're proposed for your inclusion. Separately, I've made the permissions on your CI/CD as minimal as possible and removed a very minor source of on-disk credential persistence via actions/checkout.

With these changes, the only remaining default zizmor finding is this:

warning[secrets-outside-env]: secrets referenced without a dedicated environment
--> ./.github/workflows/build.yml:82:20
|
18 | build:
| ----- this job
...
82 | token: ${{ secrets.CODECOV_ORG_TOKEN }}
| ^^^^^^^^^^^^^^^^^^^^^^^^^ secret is accessed outside of a dedicated environment
|
= note: audit confidence → High
3 findings (2 suppressed): 0 informational, 0 low, 1 medium, 0 high

...which is pretty minor, but could be resolved by a maintainer by moving that credential into a dedicated deployment environment.

Separately, I have not included a CI integration for zizmor in this PR. But if you're interested in one LMK and I'd be happy to do a follow up PR for it!

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@zooba

Copy link
Copy Markdown
Member

Thanks. We'll see how dependabot goes, I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down. Is there a way to make sure it's constrained to only complain about important stuff (such as pipelines) and not (e.g.) test data?

@woodruffw

Copy link
Copy Markdown
ContributorAuthor

I find it mostly annoying in every scenario and so it tends to manage about 5 notifications before I shut it down

Same 😅 -- what I've done here is configure Dependabot to hopefully be a bit less noisy than the defaults: the current config will only run update checks once a week, and will batch all updates into a single PR. I've also only enabled the github-actions updater, so Dependabot shouldn't nag you with Python dep bumps or anything else.

(It's very easy to further ratchet that down as well, e.g. to only do updates every month or even every quarter. Whatever works for you, I'm happy to amend to!)

@zooba

Copy link
Copy Markdown
Member

Batching all updates is finally here ❤️

Let's do it. I'm in the middle of pinning other build-time dependencies, but I wouldn't have got these, so the PR is well timed.

@zooba
zooba merged commit 3efddd1 into python:mainApr 13, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@woodruffw@zooba