* ci: pin actions to SHAs and harden workflows with zizmor auto-fixes
* ci: set least-privilege GITHUB_TOKEN permissions on workflows
* ci: move PR/issue context into env vars to prevent template injection
* Fix python-tests workflow: split get_sample_dirs into its own job
The build job declares `needs: get_sample_dirs`, but get_sample_dirs was
defined as a step inside build rather than as a separate job. This caused
GitHub Actions to reject the workflow with:
The workflow must contain at least one job with no dependencies.
This commit:
- Extracts get_sample_dirs into its own job with proper outputs
- Replaces undefined $PYTHON_DIR with the actual path (samples/python)
- Formats the find output as JSON array for fromJson() compatibility
- Adds an if condition to skip the build matrix when no samples exist
Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com>
* Update actions/checkout from v4 to v6
---------
Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com>
Co-authored-by: Kristopher Overholt <koverholt@google.com>