• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

Ouranosinc / xclim / 7613329127
90%
main: 92%

Build:
Build:
LAST BUILD BRANCH: support-socket-blocked
DEFAULT BRANCH: main
Ran 22 Jan 2024 03:22PM UTC
Jobs 2
Files 70
Run time 8s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

22 Jan 2024 03:16PM UTC coverage: 90.268% (-0.02%) from 90.284%
7613329127

push

github

web-flow
[StepSecurity] Apply security best practices (#1606)

## Summary

This pull request is created by
[StepSecurity](https://app.stepsecurity.io/securerepo) at the request of
@Zeitsperre. Please merge the Pull Request to incorporate the requested
changes. Please tag @Zeitsperre on your message if you have any
questions related to the PR.
## Security Fixes

### Pinned Dependencies

GitHub Action tags and Docker tags are mutatble. This poses a security
risk. GitHub's Security Hardening guide recommends pinning actions to
full length commit.

- [GitHub Security
Guide](https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions)
- [The Open Source Security Foundation (OpenSSF) Security
Guide](https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies)
### Keeping your actions up to date with Dependabot

With Dependabot version updates, when Dependabot identifies an outdated
dependency, it raises a pull request to update the manifest to the
latest version of the dependency. This is recommended by GitHub as well
as The Open Source Security Foundation (OpenSSF).

- [GitHub Security
Guide](https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot)
- [The Open Source Security Foundation (OpenSSF) Security
Guide](https://github.com/ossf/scorecard/blob/main/docs/checks.md#dependency-update-tool)
### Maintain Code Quality with Pre-Commit

Pre-commit is a framework for managing and maintaining multi-language
pre-commit hooks. Hooks can be any scripts, code, or binaries that run
at any stage of the git workflow. Pre-commit hooks are useful for
enforcing code quality, code formatting, and detecting security
vulnerabilities.

- [Official Pre-commit documentation](https://pre-commit.com/)
- [Getting Started guide](https://pre-commit.com/#getting-started)


## Feedback
For bug reports, featur... (continued)

8635 of 9566 relevant lines covered (90.27%)

4.36 hits per line

Jobs
ID Job ID Ran Files Coverage
1 run-{{ matrix.tox-env }}-opt-slow - 7613329127.1 22 Jan 2024 10:00PM UTC 0
89.82
2 run-{{ matrix.tox-env }} - 7613329127.2 22 Jan 2024 10:00PM UTC 0
90.27
Source Files on build 7613329127
Detailed source file information is not available for this build.
  • Back to Repo
  • 4aeabc2b on github
  • Prev Build on master (#7561629014)
  • Next Build on master (#7617005742)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc