Skip to content

Enable zizmor GitHub Advanced Security upload#307

Closed
tashian wants to merge 2 commits intomainfrom
carl/disable-ghas-by-default
Closed

Enable zizmor GitHub Advanced Security upload#307
tashian wants to merge 2 commits intomainfrom
carl/disable-ghas-by-default

Conversation

@tashian
Copy link
Copy Markdown
Contributor

@tashian tashian commented Mar 3, 2026

Summary

  • Explicitly enable zizmor-advanced-security: true for this public repo
  • Required because the actionci.yml default is being changed to false in smallstep/workflows

🤖 Generated with Claude Code

Public repos need to explicitly enable GHAS upload now that the
actionci.yml default has been changed to false.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@tashian tashian requested review from a team and maraino as code owners March 3, 2026 16:59
permissions:
contents: read
security-events: write
uses: smallstep/workflows/.github/workflows/actionci.yml@main

Check failure

Code scanning / zizmor

unpinned action reference Error

unpinned action reference
permissions:
contents: read
security-events: write
uses: smallstep/workflows/.github/workflows/actionci.yml@main

Check warning

Code scanning / zizmor

secrets unconditionally inherited by called workflow Warning

secrets unconditionally inherited by called workflow
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@tashian tashian closed this Mar 3, 2026
@hslatman hslatman changed the title ci: Enable zizmor GitHub Advanced Security upload Enable zizmor GitHub Advanced Security upload Mar 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants