Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

integrate zizmor #474

Open
jku opened this issue Nov 18, 2024 · 2 comments
Open

integrate zizmor #474

jku opened this issue Nov 18, 2024 · 2 comments

Comments

@jku
Copy link
Member

jku commented Nov 18, 2024

zizmor is a GH actions audit tool, I'm hoping it works on actual actions yml as well (and not just workflow files): this would be very useful for the tuf-on-ci actions...

@jku
Copy link
Member Author

jku commented Nov 18, 2024

I'm hoping it works on actual actions yml as well (and not just workflow files)

Unfortunately it does not at this moment... Running it on our own workflows is still useful as it does find some issues.

@jku
Copy link
Member Author

jku commented Jan 17, 2025

zizmor has some support for actions now

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant