From 8e8a0c98b8a28e824bfa738c8057fef32b5a4c06 Mon Sep 17 00:00:00 2001 From: Douglas Eichelberger Date: Tue, 29 Sep 2026 14:10:17 -0700 Subject: [PATCH] Fix the stale checkout version comment in cd.yml Dependabot bumped the checkout SHA to v7.0.1 in #30 but left the comment at v7.0.0, most likely because the zizmor ignore followed it on the same line. The ignore moves to the with: line, next to an explicit persist-credentials: true, so the version comment stands alone and Dependabot can update it. Checkout already persists credentials by default, so behavior doesn't change. --- .github/workflows/cd.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/cd.yml b/.github/workflows/cd.yml index 3b3b2ba..daf517e 100644 --- a/.github/workflows/cd.yml +++ b/.github/workflows/cd.yml @@ -11,7 +11,9 @@ jobs: # `rake release`, which does a raw `git push` and never re-authenticates from GITHUB_TOKEN itself; it # relies entirely on the credential this checkout step leaves behind. Disabling persistence breaks every # deploy with "fatal: could not read Username for 'https://github.com'". - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.0 # zizmor: ignore[artipacked] persisted credentials required for the git push in "Tag and Push Gem" below + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: # zizmor: ignore[artipacked] persisted credentials required for the git push in "Tag and Push Gem" below + persist-credentials: true - name: Tag and Push Gem id: tag-and-push-gem uses: discourse/publish-rubygems-action@4bd305c65315cb691bad1e8de97a87aaf29a0a85 # v3