mirror of
https://github.com/pypa/pip.git
synced 2026-03-28 02:21:27 +00:00
Already used by other PyPA projects (packaging, build, warehouse), recommended by Seth. Auto-fixed: added cooldown config to dependabot entries. Manually fixed: - Added persist-credentials: false to all checkout steps - Added permissions blocks to ci.yml, release.yml, update-rtd-redirects.yml - Pinned all actions to commit hashes (release.yml was already pinned)