Skip to content

[Feature] Add zizmor for GitHub Actions #54

@GhostofGoes

Description

@GhostofGoes

Add zizmor for GitHub Actions

Summary

Check GitHub Actions for security issues using zizmor.

Motivation

Improve security of our Actions, especially in light of the Tivy compromise.

Proposed Solution

Implement a Actions workflow and pre-commit config that checks zizmor. Bring current actions into compliance with any checks.

Alternatives Considered

No.

Additional Context

Relevant example from Pydantic: https://github.com/pydantic/pydantic/pull/13039/changes#diff-63a9c44a44acf85fea213a857769990937107cf072831e1a26808cfde9d096b9

Checklist

  • I have included no proprietary/sensitive information in my issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request
    No fields configured for Feature.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions