Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Zizmor #415

Merged
merged 1 commit into from
Jan 15, 2025
Merged

Add Zizmor #415

merged 1 commit into from
Jan 15, 2025

Conversation

jfantinhardesty
Copy link
Contributor

What type of Pull Request is this? (check all applicable)

  • Refactor
  • Feature
  • Bug Fix
  • Optimization
  • Documentation Update

Describe your changes in brief

This adds Zizmor to our CI/CD pipeline to check for security issues with our GitHub actions following their setup here https://woodruffw.github.io/zizmor/usage/#integration. This also fixes any remaining issues that Zizmor found which includes not using the cache during release to prevent cache pollution attacks.

Checklist

  • Tested locally
  • Added new dependencies
  • Updated documentation
  • Added tests

Related Issues

  • Related Issue #
  • Closes #

Copy link
Contributor

@foodprocessor foodprocessor left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice rainbow!

@jfantinhardesty jfantinhardesty merged commit 5c33643 into main Jan 15, 2025
18 of 19 checks passed
@jfantinhardesty jfantinhardesty deleted the add-zizmor branch January 15, 2025 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants