Skip to content

add zizmor to scan workflows#5945

Merged
davidism merged 1 commit intostablefrom
zizmor
Mar 8, 2026
Merged

add zizmor to scan workflows#5945
davidism merged 1 commit intostablefrom
zizmor

Conversation

@davidism
Copy link
Copy Markdown
Member

@davidism davidism commented Mar 8, 2026

https://docs.zizmor.sh/

Among the findings:

  • apply empty permissions with permissions: {}, although we have read only defaults set at the organization level
  • use concurrency group for each workflow
  • disable credentials for checkout
  • remove some template variables in favor of env vars

@davidism davidism merged commit 4774385 into stable Mar 8, 2026
15 of 16 checks passed
@davidism davidism deleted the zizmor branch March 8, 2026 23:15
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Mar 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant