Skip to content

ci: adopt zizmor for GitHub Actions security #22

Description

@hasansezertasan

Context

zizmor is a static analysis tool for GitHub Actions workflows that catches injection, excessive permissions, unpinned actions, and other CI supply-chain issues.

Proposed tasks

  • Add a zizmor job (or pre-commit hook) scanning .github/workflows/
  • Triage & fix initial findings (likely: pin actions to SHAs, tighten permissions:)
  • Wire into CI as a required check

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    ciThis is CI relatedinfraThis is Infrastructure related

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions