Skip to content

feat: Add zizmor pre commit hook#132

Merged
ytausch merged 4 commits intomainfrom
add-zizmor
Mar 9, 2026
Merged

feat: Add zizmor pre commit hook#132
ytausch merged 4 commits intomainfrom
add-zizmor

Conversation

@ManuelLerchnerQC
Copy link
Contributor

  • Add zizmor as a pre-commit hook for auditing GitHub Actions workflows
  • Add zizmor to lint dependencies in both the root pixi.toml and template/pixi.toml.jinja
  • Fix zizmor findings:
    • add persist-credentials: false to all actions/checkout steps
    • add cooldown config to dependabot.yml.

All rendered workflow templates pass zizmor with zero findings

@ytausch ytausch merged commit d717d56 into main Mar 9, 2026
5 checks passed
@ytausch ytausch deleted the add-zizmor branch March 9, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants