Skip to content

ci(security): avoid persisting credentials on checkout#24

Merged
JonZeolla merged 2 commits intomainfrom
avoid-persisting-creds
Jul 8, 2025
Merged

ci(security): avoid persisting credentials on checkout#24
JonZeolla merged 2 commits intomainfrom
avoid-persisting-creds

Conversation

@JonZeolla
Copy link
Copy Markdown
Member

Contributor Comments

This ensures we don't persist creds on checkout; according to my testing it is not necessary and it's generally unsafe (even though it is the actions/checkout default). When we implement zizmor in the future (on our roadmap), this will be enforced via CI but for now we're adding it as best effort.

Pull Request Checklist

Thank you for submitting a contribution!

Please address the following items:

  • If you are adding a dependency, please explain how it was chosen.
  • If manual testing is needed in order to validate the changes, provide a testing plan and the expected results.
  • Validate that documentation is accurate and aligned to any project updates or additions.

@JonZeolla JonZeolla enabled auto-merge (squash) July 8, 2025 18:00
Copy link
Copy Markdown

@ai-coding-guardrails ai-coding-guardrails Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work! 😎

I didn't find anything of concern

Reviewed with 🤟 by Zenable

@JonZeolla JonZeolla merged commit a4709d5 into main Jul 8, 2025
7 checks passed
@JonZeolla JonZeolla deleted the avoid-persisting-creds branch July 8, 2025 18:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant