Skip to content

ci: add zizmor workflow linting#4909

Open
omribz156 wants to merge 1 commit into
containerd:mainfrom
omribz156:codex/add-zizmor
Open

ci: add zizmor workflow linting#4909
omribz156 wants to merge 1 commit into
containerd:mainfrom
omribz156:codex/add-zizmor

Conversation

@omribz156
Copy link
Copy Markdown

Summary:

  • Add zizmor to the workflow lint CI.
  • Fix the workflow findings reported by zizmor, including token persistence, excessive permissions, setup-go caching, and template-injection warnings.

Verification:

  • uvx zizmor .github/workflows
  • C:\Users\omrib\go\bin\actionlint.exe -ignore 'not assignable' -ignore 'property "hack" is not defined'
  • git diff --check

Note: raw actionlint reports the same existing baseline findings on clean origin/main and this branch. With those baseline findings ignored, this branch does not add new actionlint findings.

This was implemented with Codex assistance, with the final diff reviewed before posting.

Signed-off-by: Omri SirComp <omribz156@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant