Skip to content

Add zizmor for GitHub Actions workflow security audit #385

@aallan

Description

@aallan

zizmor audits workflow files for injection vulnerabilities, overly permissive permissions, and other security issues specific to GitHub Actions.

pip install zizmor
zizmor .github/workflows/

Especially relevant because the CI handles secrets (CODECOV_TOKEN, GITHUB_TOKEN). Run locally first, fix any findings, then add to the lint CI job.

Metadata

Metadata

Assignees

No one assigned

    Labels

    ciCI/CD and GitHub Actions

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions