Skip to content

Run zizmor over all GitHub Actions workflow files #4933

@agriyakhetarpal

Description

@agriyakhetarpal

https://github.com/woodruffw/zizmor is a static analysis tool for GitHub Actions that we should use to evaluate and improve the security of our repository.

Here's the documentation: https://woodruffw.github.io/zizmor/

  • Run zizmor over all workflow files with the --pedantic option
  • Address all issues raised by it
  • Add it as a pre-commit hook

Metadata

Metadata

Assignees

Labels

CI/CDRelated to continuous integration, continuous deployment (GitHub Actions, workflows, testing, etc.)difficulty: easyA good issue for someone new. Can be done in a few hourspriority: mediumTo be resolved if time allows

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions