Skip to content

Address zizmor findings: - #149

Open
cpovirk wants to merge 1 commit into
mainfrom
ziz
Open

Address zizmor findings:#149
cpovirk wants to merge 1 commit into
mainfrom
ziz

Conversation

@cpovirk

@cpovirk cpovirk commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

I've focused only on our custom CI configuration, not on the CI configuration from upstream: I'm not even sure whether we run the upstream configuration, and even if we do, I'd prefer not to introduce changes (fairly invasive ones in some cases!) that might lead to merge conflicts. Ideally we'd do better someday, including trying to make changes upstream.

- [`persist-credentials: false`](https://docs.zizmor.sh/audits/#artipacked)
- [pinning `uses`](https://docs.zizmor.sh/audits/#unpinned-uses)

I've focused only on our custom CI configuration, not on the CI configuration from upstream: I'm not even sure whether we run the upstream configuration, and even if we do, I'd prefer not to introduce changes (fairly invasive ones in some cases!) that might lead to merge conflicts. Ideally we'd do better someday, including trying to make changes upstream.
@cpovirk

cpovirk commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator Author

I'm not even sure whether we run the upstream configuration

It looks like we "Prepare" but do nothing else:
image

Now presumably it would be nice to pin actions for that step and perhaps make other changes. Or we could delete that configuration entirely (at the cost of having to tell Git to ignore changes to those deleted files when we see merge conflicts).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant