Skip to content

Conversation

csmarchbanks
Copy link
Contributor

@csmarchbanks csmarchbanks commented Apr 28, 2025

Run zizmor and fix the findings, mainly around needlessly persisting credentials, and using non-pinned versions of third party actions.

You can test by installing zizmor, and running in this repo:

zizmor .github

which now gives:

 INFO zizmor: skipping forbidden-uses: audit not configured
 INFO audit: zizmor: 🌈 completed .github/workflows/go.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/release.yml
No findings to report. Good job! (1 suppressed)

@csmarchbanks csmarchbanks requested a review from a team as a code owner April 28, 2025 22:50
Run zizmor and fix the findings, mainly around needlessly persisting
credentials, and using non-pinned versions of third party actions.
Copy link
Contributor

@ioanarm ioanarm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚀

@csmarchbanks csmarchbanks merged commit 94c5a84 into main Apr 29, 2025
5 checks passed
@csmarchbanks csmarchbanks deleted the fix-zizmor-findings branch April 29, 2025 12:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants