-
-
Notifications
You must be signed in to change notification settings - Fork 748
Closed
Labels
CI/CDRelated to continuous integration, continuous deployment (GitHub Actions, workflows, testing, etc.)Related to continuous integration, continuous deployment (GitHub Actions, workflows, testing, etc.)difficulty: easyA good issue for someone new. Can be done in a few hoursA good issue for someone new. Can be done in a few hourspriority: mediumTo be resolved if time allowsTo be resolved if time allows
Description
https://github.com/woodruffw/zizmor is a static analysis tool for GitHub Actions that we should use to evaluate and improve the security of our repository.
Here's the documentation: https://woodruffw.github.io/zizmor/
- Run zizmor over all workflow files with the
--pedanticoption - Address all issues raised by it
- Add it as a pre-commit hook
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
CI/CDRelated to continuous integration, continuous deployment (GitHub Actions, workflows, testing, etc.)Related to continuous integration, continuous deployment (GitHub Actions, workflows, testing, etc.)difficulty: easyA good issue for someone new. Can be done in a few hoursA good issue for someone new. Can be done in a few hourspriority: mediumTo be resolved if time allowsTo be resolved if time allows