Skip to content

fix(ci): enforce github actions security with zizmor#5134

Merged
baszalmstra merged 4 commits intoprefix-dev:mainfrom
Hofer-Julian:fix/zizmor
Dec 16, 2025
Merged

fix(ci): enforce github actions security with zizmor#5134
baszalmstra merged 4 commits intoprefix-dev:mainfrom
Hofer-Julian:fix/zizmor

Conversation

@Hofer-Julian
Copy link
Contributor

@Hofer-Julian Hofer-Julian commented Dec 15, 2025

Description

Use zizmor to enforce safe practices with github actions.
Only severity high for now, since some of the lower priorities would involve bigger refactors

  • Use pinned sha for setup-pixi
  • Use safer pull_request instead of pull_request_target which has access to all secrets even across forks
  • Access input with env vars. That was fine before as well, since only we trigger that, but it doesn't hurt either.

How Has This Been Tested?

pixi run zizmor

AI Disclosure

  • This PR contains AI-generated content.
    • I have tested any AI-generated content in my PR.
    • I take responsibility for any AI-generated content in my PR.

Tools: Claude

Checklist:

  • I have performed a self-review of my own code

@Hofer-Julian Hofer-Julian marked this pull request as ready for review December 15, 2025 14:38
@baszalmstra baszalmstra merged commit 5a29dd6 into prefix-dev:main Dec 16, 2025
56 checks passed
@Hofer-Julian Hofer-Julian deleted the fix/zizmor branch December 16, 2025 08:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants