Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Update download-artifact plugin in publish-to-test-pypi.yml to fix vu…
…lnerability Versions of actions/download-artifact before 4.1.7 are vulnerable to arbitrary file write when downloading and extracting a specifically crafted artifact that contains path traversal filenames. Fore more details see: GHSA-6q32-hq47-5qq3
- Loading branch information