Skip to content

fix: safety ci using static check zizmor#1123

Merged
Xuanwo merged 1 commit intoapache:mainfrom
yihong0618:hy/safety_ci
Mar 24, 2025
Merged

fix: safety ci using static check zizmor#1123
Xuanwo merged 1 commit intoapache:mainfrom
yihong0618:hy/safety_ci

Conversation

@yihong0618
Copy link
Contributor

Which issue does this PR close?

this patch make ci more safety using static check zizmor: to avoid code injection

more:

and github actions safety is more and more important:

link: https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised

Signed-off-by: yihong0618 <zouzou0208@gmail.com>
Copy link
Member

@Xuanwo Xuanwo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you, nice change!

@Xuanwo Xuanwo merged commit 4185e37 into apache:main Mar 24, 2025
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants