python-tuf/.github/workflows
Jussi Kukkonen b6c3b66ca6 build: Change build dependency pinning strategy
* don't autoupgrade pip: let's consider pip to be part of platform?
* pin build and tox in new requirements-build.txt: this mostly prevents
  tox from going to 4.x before we're ready
* use requirements-build.txt as constraint when installing tox or build
  during CI & CD
* use requirements-build.txt in requiremenets-dev.txt

Note that coveralls is not pinned, not sure if it should be.

Signed-off-by: Jussi Kukkonen <jkukkonen@google.com>
2022-12-09 18:10:03 +02:00
..
_test.yml build: Change build dependency pinning strategy 2022-12-09 18:10:03 +02:00
cd.yml build: Change build dependency pinning strategy 2022-12-09 18:10:03 +02:00
ci.yml workflows: Set top-level permissions 2022-10-30 12:56:22 +02:00
codeql-analysis.yml build(deps): bump github/codeql-action from 2.1.33 to 2.1.35 2022-12-02 10:04:16 +00:00
dependency-review.yml build(deps): bump actions/dependency-review-action from 3.0.0 to 3.0.1 2022-11-17 10:11:44 +00:00
maintainer-permissions-reminder.yml build(deps): bump actions/github-script from 6.3.2 to 6.3.3 2022-10-14 10:16:54 +00:00
scorecards.yml build(deps): bump github/codeql-action from 2.1.33 to 2.1.35 2022-12-02 10:04:16 +00:00
specification-version-check.yml build: Change build dependency pinning strategy 2022-12-09 18:10:03 +02:00