kpumuk opened a new pull request, #3718:
URL: https://github.com/apache/thrift/pull/3718
<!-- Explain the changes in the pull request below: -->
Fix the open zizmor findings in the GitHub Actions workflows. This updates
the `setup-php` version comments to match their pinned commit and installs
Node.js dependencies from the committed lockfiles.
The ASF allowlist check now follows the [Apache infrastructure-actions
documentation](https://github.com/apache/infrastructure-actions/blob/main/allowlist-check/README.md),
which specifies installation from `@main`. A narrowly scoped zizmor policy
permits symbolic references for that composite action while retaining the
default hash-pin requirement for every other action.
<!-- We recommend you review the checklist/tips before submitting a pull
request. -->
- [ ] Did you create an [Apache
Jira](https://issues.apache.org/jira/projects/THRIFT/issues/) ticket?
([Request account here](https://selfserve.apache.org/jira-account.html), not
required for trivial changes)
- [ ] If a ticket exists: Does your pull request title follow the pattern
"THRIFT-NNNN: describe my issue"?
- [x] Did you squash your changes to a single commit? (not required, but
preferred)
- [x] Did you do your best to avoid breaking changes? If one was needed,
did you label the Jira ticket with "Breaking-Change"?
- [ ] If your change does not involve any code, include `[skip ci]` anywhere
in the commit message to free up build resources.
<!--
The Contributing Guide at:
https://github.com/apache/thrift/blob/master/CONTRIBUTING.md
has more details and tips for committing properly.
-->
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]