Skip to content

[pre-commit.ci] pre-commit autoupdate#548

Open
pre-commit-ci[bot] wants to merge 1 commit intomasterfrom
pre-commit-ci-update-config
Open

[pre-commit.ci] pre-commit autoupdate#548
pre-commit-ci[bot] wants to merge 1 commit intomasterfrom
pre-commit-ci-update-config

Conversation

@pre-commit-ci
Copy link
Copy Markdown
Contributor

@pre-commit-ci pre-commit-ci Bot commented Apr 6, 2026

updates:
- [github.com/zizmorcore/zizmor-pre-commit: v1.22.0 → v1.23.1](zizmorcore/zizmor-pre-commit@v1.22.0...v1.23.1)
- [github.com/astral-sh/uv-pre-commit: 0.9.28 → 0.11.3](astral-sh/uv-pre-commit@0.9.28...0.11.3)
- [github.com/astral-sh/ruff-pre-commit: v0.14.13 → v0.15.9](astral-sh/ruff-pre-commit@v0.14.13...v0.15.9)
@neutrinoceros
Copy link
Copy Markdown
Collaborator

@kwgoodman the proper fix to the newly discovered zizmor audit (secrets-outside-env) would be to setup trusted publishing and revoke the long-lived pypi token stored in this repo.

@rgommers
Copy link
Copy Markdown
Collaborator

rgommers commented Apr 7, 2026

Yes, we should set that up, that is getting more urgent with every supply chain security issue.

Not sure you pinged the right person though, should probably have been @rdbisme.

I'd be inclined to delete the API token now, because that's way too insecure - it can easily be extracted by running CI on a PR. Any objections?

@neutrinoceros
Copy link
Copy Markdown
Collaborator

I picked @kwgoodman as the first name on the maintainer list for the PyPI repo, but really anyone with clearance could step up.
I agree with deleting the token as soon as possible.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants