Skip to content

Add zizmor security scanning and improve CI/CD security#315

Merged
vonericsen merged 3 commits intoSeagate:developfrom
jfantinhardesty:feature/add-zizmor
Apr 14, 2026
Merged

Add zizmor security scanning and improve CI/CD security#315
vonericsen merged 3 commits intoSeagate:developfrom
jfantinhardesty:feature/add-zizmor

Conversation

@jfantinhardesty
Copy link
Copy Markdown
Contributor

This PR adds Zizmor to the CI/CD pipeline. Zizmor is a tool that scans GitHub Actions and then finds security issues with the way they are setup. We have been using it in our cloudfuse project for a few months and found it very useful. This can help prevent compromises to released packages, etc. that have been becoming very common in the past few months.

I also took a stab at trying to apply fixes for the issues it identified. There are likely a few issues here than can only be identified when running the CI/CD pipelines. Hoping we can have a bit of a back and forth to fix any issues with the runs.

…CI/CD security

Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>
Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>
Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>
@vonericsen vonericsen merged commit 0a5c5a4 into Seagate:develop Apr 14, 2026
54 of 56 checks passed
@vonericsen
Copy link
Copy Markdown
Contributor

Thanks for these changes!

vonericsen pushed a commit that referenced this pull request Apr 15, 2026
* Add zizmor to github actions and fix warnings from zizmor to improve CI/CD security

Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>

* Update publish step to use GitHub CLI for release management.

Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>

* Update opensea-common subproject to latest commit

Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>

---------

Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>
Signed-off-by: Tyler Erickson <tyler.erickson@seagate.com>
# Conflicts:
#	.github/workflows/meson.yml
#	.github/workflows/msbuild.yml
#	.github/workflows/source-release.yml
#	subprojects/opensea-common
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants