Skip to content

feat(zizmor): Add Zizmor Static Analysis - #18628

Merged
vpomerleau merged 1 commit into
mozilla:mainfrom
bkochendorfer:zizmor-static-analysis
Apr 24, 2025
Merged

feat(zizmor): Add Zizmor Static Analysis#18628
vpomerleau merged 1 commit into
mozilla:mainfrom
bkochendorfer:zizmor-static-analysis

Conversation

@bkochendorfer

@bkochendorfer bkochendorfer commented Mar 28, 2025

Copy link
Copy Markdown
Member

This pull request

Zizmor is a Static Analysis tool for GitHub Actions https://woodruffw.github.io/zizmor/usage/#use-in-github-actions

Ran Zizmor locally to fix up any open issues on existing GitHub Actions. There are some caching features which were disabled based on https://woodruffw.github.io/zizmor/audits/#cache-poisoning

Checklist

Put an x in the boxes that apply

  • My commit is GPG signed.
  • If applicable, I have modified or added tests which pass locally.
  • I have added necessary documentation (if appropriate).
  • I have verified that my changes render correctly in RTL (if appropriate).

Screenshots (Optional)

Please attach the screenshots of the changes made in case of change in user interface.

Other information (Optional)

Any other information that is important to this pull request.

Zizmor is a Static Analysis tool for GitHub Actions https://woodruffw.github.io/zizmor/usage/#use-in-github-actions

Ran Zizmor locally to fix up any open issues on existing github actions.
@bkochendorfer
bkochendorfer requested a review from a team as a code owner March 28, 2025 20:16
@vpomerleau

Copy link
Copy Markdown
Contributor

Reverted, this workflow was causing PRs to fail.
To enable, need to either set uses policy to ref-pin or update actions with SHA reference (see https://woodruffw.github.io/zizmor/audits/#unpinned-uses-configuration)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants