Skip to content

Use zizmor to lint GitHub action workflows#613

Merged
mweinelt merged 3 commits intomainfrom
zizmor-lints
Apr 6, 2025
Merged

Use zizmor to lint GitHub action workflows#613
mweinelt merged 3 commits intomainfrom
zizmor-lints

Conversation

@mweinelt
Copy link
Copy Markdown
Member

@mweinelt mweinelt commented Apr 6, 2025

Inspired by NixOS/nixpkgs#396451.

Our security posture needs to be at least as good as that of nixpkgs, if not better 😉

@mweinelt mweinelt requested a review from a team as a code owner April 6, 2025 14:14
@mweinelt mweinelt force-pushed the zizmor-lints branch 4 times, most recently from f33b396 to d7220f3 Compare April 6, 2025 14:21
@github-advanced-security
Copy link
Copy Markdown

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@mweinelt mweinelt force-pushed the zizmor-lints branch 4 times, most recently from e6f9a90 to 988161d Compare April 6, 2025 14:39
@mweinelt
Copy link
Copy Markdown
Member Author

mweinelt commented Apr 6, 2025

This is ready. PTAL

Copy link
Copy Markdown
Contributor

@jfly jfly left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Neat tool! TIL about the artipacked attack :(

@mweinelt mweinelt added this pull request to the merge queue Apr 6, 2025
Merged via the queue into main with commit 5ef9e23 Apr 6, 2025
15 checks passed
@mweinelt mweinelt deleted the zizmor-lints branch April 6, 2025 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants