Skip to content

chore: workflow hardening — pinact + zizmor [automated]#5

Open
infra-hardening[bot] wants to merge 1 commit into
mainfrom
workflow-hardening/zizmor-2026-06-19
Open

chore: workflow hardening — pinact + zizmor [automated]#5
infra-hardening[bot] wants to merge 1 commit into
mainfrom
workflow-hardening/zizmor-2026-06-19

Conversation

@infra-hardening

Copy link
Copy Markdown

Automated workflow hardening

This PR was generated by the pt-infra-hardening pipeline.

Changes

.github/workflows/frogbot.yml — pinact

  • Pinned jfrog/frogbot@v2jfrog/frogbot@05cf3f3ac9585235160476409b2cda3ba12471b0 # v2.34.2

⚠️ Needs human attention

These findings could not be fixed automatically and need a maintainer's decision:

  • .github/workflows/frogbot.yml:3zizmor/dangerous-triggers: pull_request_target is almost always used insecurely and requires careful human review to ensure it cannot be exploited by untrusted PRs. → https://docs.zizmor.sh/audits/#dangerous-triggers

    Once reviewed and accepted, prevent future runs from re-flagging this by adding an inline suppression comment on the offending line in .github/workflows/frogbot.yml:

    # zizmor: ignore[dangerous-triggers] <your reason here>

    Replace <your reason here> with a brief justification.


Suppressing findings

To prevent a finding from being flagged in future hardening runs — whether it was fixed automatically or flagged for manual review — add an inline comment on the relevant line:

# zizmor: ignore[<rule-name>] <your reason here>

Replace <rule-name> with the audit name (e.g. artipacked, secrets-inherit). See zizmor audit docs for all rule names.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

0 participants