Vouch request: enbiyagoral #3968
enbiyagoral
started this conversation in
Vouch Request
Replies: 3 comments
|
The changes are ready here, feel free to take a look: main...enbiyagoral:OpenShell:ci/harden-workflows |
0 replies
|
Nice work! I’m also exploring OpenShell as a first-time contributor, and it’s great to see contributors looking beyond features and improving the security foundation. The zizmor findings and the decision to leave image pinning for maintainers’ consideration make the scope clear. Looking forward to seeing how this evolves. |
0 replies
|
thanks! honestly, i'm curious too. we'll wait and see |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What do you want to work on?
I ran zizmor locally using the same settings as workflow-security.yml and found 29 high severity findings. I’d like to fix 12 of them across 7 workflow files, mostly template injection and excessive permissions. I’m leaving the unpinned-images findings out for now since pinning ci:latest to a digest feels like something the maintainers should decide
Why this change?
The goal is to reduce the high severity CI findings without changing the intended workflow behavior. After the changes, zizmor goes from 29 to 17 high findings and actionlint passes.
Checklist
All reactions