Skip to content

Add zizmor checks for GitHub 操作 - #16314

Merged
AlexWaygood merged 2 commits into
mainfrom
alex/zizmor
Aug 29, 2026
Merged

Add zizmor checks for GitHub 操作#16314
AlexWaygood merged 2 commits into
mainfrom
alex/zizmor

Conversation

@AlexWaygood

Copy link
Copy Markdown
Member

Add zizmor security checks for GitHub 操作 and address their findings by restricting credentials and permissions, safely passing the base ref to Bash, and documenting the required workflow_run trigger.

Stacked on #16313.

Assisted by Codex.

@github-actions

This comment has been minimized.

@AlexWaygood
AlexWaygood marked this pull request as ready for review August 28, 2026 14:29
Comment thread .pre-commit-config.yaml Outdated
@github-actions

This comment has been minimized.

Base automatically changed from alex/pin-github-actions to main August 29, 2026 12:52
@github-actions

Copy link
Copy Markdown
Contributor

According to mypy_primer, this change has no effect on the checked open source code. 🤖🎉

@AlexWaygood
AlexWaygood merged commit 353c7ba into main Aug 29, 2026
127 checks passed
@AlexWaygood
AlexWaygood deleted the alex/zizmor branch August 29, 2026 13:03
Comment thread .pre-commit-config.yaml
- repo: https://github.com/zizmorcore/zizmor-pre-commit
rev: 451b56af716f9f0d0c2b816503a3fd0cf8b036fa # frozen: v1.29.0
hooks:
- id: zizmor

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- id: zizmor
- id: zizmor
args: [--no-progress, --fix]

Would you consider these hook args in order to autofix issues when they come up?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes I would! Want to make a PR? Thanks!

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

注册 for free to join this conversation on GitHub. Already have an account? 登录 to comment

标签

None yet

项目

None yet

Development

Successfully merging this pull request may close these issues.

3 participants