Skip to content

ci: adopt zizmor for GitHub Actions security #22

Description

@hasansezertasan

Context

zizmor is a static analysis tool for GitHub Actions workflows that catches injection, excessive permissions, unpinned actions, and other CI supply-chain issues.

Proposed tasks

  • Add a zizmor job (or pre-commit hook) scanning .github/workflows/
  • Triage & fix initial findings (likely: pin actions to SHAs, tighten permissions:)
  • Wire into CI as a required check

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ciThis is CI relatedinfraThis is Infrastructure related

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions