diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e0ba49e..3ee1470 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,8 +4,12 @@ updates: directory: "/" schedule: interval: "daily" - + cooldown: + default-days: 7 + - package-ecosystem: "github-actions" directory: "/" schedule: interval: "daily" + cooldown: + default-days: 7 diff --git a/.github/workflows/ci-build.yml b/.github/workflows/ci-build.yml index 17a2b0a..038e9fe 100644 --- a/.github/workflows/ci-build.yml +++ b/.github/workflows/ci-build.yml @@ -5,6 +5,9 @@ on: - main pull_request: +permissions: + contents: read + jobs: build: name: Build and Test @@ -12,7 +15,9 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Build run: | diff --git a/.github/workflows/ci-release.yml b/.github/workflows/ci-release.yml index 5cbaa8a..504b7a3 100644 --- a/.github/workflows/ci-release.yml +++ b/.github/workflows/ci-release.yml @@ -5,33 +5,27 @@ on: name: Upload Release Asset +permissions: + contents: write + jobs: build: name: Upload Release Asset runs-on: ubuntu-latest steps: - name: Checkout code - uses: actions/checkout@v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - name: Build project run: | make && mv https-redirect https-redirect_linux_amd64 - - name: Create Release - id: create_release - uses: actions/create-release@v1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - tag_name: ${{ github.ref }} - release_name: ${{ github.ref }} - draft: true - prerelease: false - - name: Upload Release Asset - id: upload-release-asset - uses: actions/upload-release-asset@v1 + + - name: Create Release and Upload Asset + run: | + gh release create "${GITHUB_REF_NAME}" ./https-redirect_linux_amd64 \ + --title "${GITHUB_REF_NAME}" \ + --draft env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./https-redirect_linux_amd64 - asset_name: https-redirect_linux_amd64 - asset_content_type: application/octet-stream + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}