Skip to content

Secure GHA with zizmor - #400

Open
gforcada wants to merge 7 commits into
2.xfrom
384-add-zizmor
Open

Secure GHA with zizmor#400
gforcada wants to merge 7 commits into
2.xfrom
384-add-zizmor

Conversation

@gforcada

@gforcada gforcada commented Aug 2, 2026

Copy link
Copy Markdown
Member

Part of #384

Note

⚠️ I'm not adding zizmor either as a GHA nor within pre-commit or such. The reason being that zizmor complains, rightfully so, about GHA not using hash-pinning, but can not update it.

pinact or tools like that can, but need to be checked first how to integrate them.

While we discuss and prototype how to best integrate it, the first quick fixes from zizmor are already worth merging IMHO.

@ericof if you run uvx zizmor . in this repository there are a few warning about some actions that you added, could you have a look whenever you have time, they are about token permissions and their scope, which I don't have enough knowledge about the actions themselves to make an estimated guess on what would be the proper fix.

@gforcada gforcada added the 04 type: enhancement making existing stuff better label Aug 2, 2026
@ericof

ericof commented Aug 2, 2026

Copy link
Copy Markdown
Member

@gforcada thanks for the heads up. I need to review all the existing workflows and actions when it comes to permissions and versions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

04 type: enhancement making existing stuff better

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants