Skip to content

fix: resolve template-injection issues and harden workflows#262

Merged
gforsyth merged 6 commits into
rapidsai:mainfrom
gforsyth:securitize
Apr 28, 2026
Merged

fix: resolve template-injection issues and harden workflows#262
gforsyth merged 6 commits into
rapidsai:mainfrom
gforsyth:securitize

Conversation

@gforsyth
Copy link
Copy Markdown
Contributor

  • fix(ci): remediate template injection risks
  • fix(ci): pin all third-party images
  • fix(ci): do not persist credentials unless needed
  • fix(ci): set permissions explicitly per-job
  • fix(ci): set secrets explicitly
  • feat(ci): add zizmor to pre-commit checks

@gforsyth gforsyth added improvement Improves an existing functionality non-breaking Introduces a non-breaking change labels Apr 27, 2026
Signed-off-by: Gil Forsyth <gforsyth@nvidia.com>
Signed-off-by: Gil Forsyth <gforsyth@nvidia.com>
Signed-off-by: Gil Forsyth <gforsyth@nvidia.com>
Signed-off-by: Gil Forsyth <gforsyth@nvidia.com>
Signed-off-by: Gil Forsyth <gforsyth@nvidia.com>
Signed-off-by: Gil Forsyth <gforsyth@nvidia.com>
@mmccarty
Copy link
Copy Markdown

@gforsyth - I'm good with an admin merge here. We don't need to revive CI as part of this work.

@gforsyth gforsyth merged commit ec2ebd5 into rapidsai:main Apr 28, 2026
7 of 8 checks passed
@gforsyth gforsyth deleted the securitize branch April 28, 2026 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

improvement Improves an existing functionality non-breaking Introduces a non-breaking change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants