Skip to content

Utilize zizmor for all github actions / workflows #82

Open
@tim-schilling

Description

@tim-schilling

Zizmor is a package that provides static analysis for github actions. Considering our broad use of github actions, it feels important we use it. It was also recommended by Seth Larson, PSF security developer in residence.

I think we should initially use it on the controls and membership repos. Then look into how we can integrate this with package repos.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestgithub-actionGitHub Actions related issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions