Skip to content

Conversation

mattip
Copy link
Member

@mattip mattip commented Dec 8, 2024

Recently there was a hack of a repo that used environment variables unsafely. While this repo "only" publishes documentation, it is better to tighten things up where possible. There is a tool called zizmor that can be used to audit workflows, I used it to develop this PR:

Copy link

netlify bot commented Dec 8, 2024

Deploy Preview for numpy-org ready!

Name Link
🔨 Latest commit ab458d1
🔍 Latest deploy log https://app.netlify.com/sites/numpy-org/deploys/67554d00c31fca0008273f20
😎 Deploy Preview https://deploy-preview-797--numpy-org.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

Copy link
Member

@rgommers rgommers left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This all LGTM, in it goes. zizmor looks like a potentially useful tool. Thanks @mattip

@rgommers rgommers merged commit fba1407 into numpy:main Dec 8, 2024
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants