From 021cbe232ca9a5d0726bdd9d2acfd8421a133caf Mon Sep 17 00:00:00 2001 From: Martin Jackson Date: Fri, 25 Sep 2026 10:56:36 -0500 Subject: [PATCH] Pin update-helm-repo reusable workflows to workflow-stable. Use the shared workflow-stable ref with zizmor ignore annotations instead of a hard-coded commit SHA. Co-authored-by: Cursor --- .github/workflows/update-helm-repo.yml | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/.github/workflows/update-helm-repo.yml b/.github/workflows/update-helm-repo.yml index 4c62cd1..7a76eb7 100644 --- a/.github/workflows/update-helm-repo.yml +++ b/.github/workflows/update-helm-repo.yml @@ -23,14 +23,12 @@ permissions: jobs: helmlint: - uses: validatedpatterns/helm-charts/.github/workflows/helmlint.yml@69fd10ef9199eecd093fca715ae9765c78750efc # October 6, 2025 + uses: validatedpatterns/helm-charts/.github/workflows/helmlint.yml@workflow-stable # zizmor: ignore[unpinned-uses] permissions: contents: read update-helm-repo: needs: [helmlint] - uses: validatedpatterns/helm-charts/.github/workflows/update-helm-repo.yml@69fd10ef9199eecd093fca715ae9765c78750efc # October 6, 2025 - permissions: - contents: read - secrets: - CHARTS_REPOS_TOKEN: ${{ secrets.CHARTS_REPOS_TOKEN }} + uses: validatedpatterns/helm-charts/.github/workflows/update-helm-repo.yml@workflow-stable # zizmor: ignore[unpinned-uses] + permissions: read-all # zizmor: ignore[excessive-permissions] + secrets: inherit # zizmor: ignore[secrets-inherit]