Harden ci workflow

This commit is contained in:
Stéphane Bidoul 2025-11-29 21:25:05 +01:00
parent 2ddd7c387a
commit 971780531e

View file

@ -8,12 +8,16 @@ on:
jobs: jobs:
test: test:
permissions:
contents: read
runs-on: ubuntu-latest runs-on: ubuntu-latest
strategy: strategy:
matrix: matrix:
python-version: ["3.13"] python-version: ["3.13"]
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@v6
with:
persist-credentials: false
- uses: actions/setup-python@v6 - uses: actions/setup-python@v6
with: with:
python-version: ${{ matrix.python-version }} python-version: ${{ matrix.python-version }}
@ -27,6 +31,9 @@ jobs:
run: mypy ./src/runboat ./tests run: mypy ./src/runboat ./tests
- uses: codecov/codecov-action@v5 - uses: codecov/codecov-action@v5
build-image: build-image:
permissions:
contents: read
packages: write
runs-on: ubuntu-latest runs-on: ubuntu-latest
needs: needs:
- test - test