diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 06586440e..14ecfedc6 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -24,9 +24,13 @@ updates: schedule: interval: "weekly" day: "sunday" + cooldown: + default-days: 7 - package-ecosystem: "maven" directory: "/" schedule: interval: "weekly" day: "sunday" open-pull-requests-limit: 5 + cooldown: + default-days: 7 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index d0f3c2a51..91baa212f 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -31,10 +31,14 @@ on: - 'doc/images/**' - 'logo/**' +permissions: {} + jobs: build: runs-on: ubuntu-latest + permissions: + contents: read strategy: fail-fast: false matrix: @@ -42,9 +46,11 @@ jobs: name: Build Parquet with JDK ${{ matrix.java }} steps: - - uses: actions/checkout@master + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Set up JDK ${{ matrix.java }} - uses: actions/setup-java@v5 + uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0 with: java-version: ${{ matrix.java }} distribution: temurin diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 000000000..ed17df02e --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,46 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +name: GitHub Actions Security Analysis with zizmor 🌈 + +on: + push: + branches: + - master + - parquet-* + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + name: Run zizmor 🌈 + runs-on: ubuntu-latest + permissions: {} + steps: + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Run zizmor 🌈 + uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 + with: + advanced-security: false + min-severity: medium + min-confidence: medium