Skip to content

security: pre-commit add zizmor static analysis for actions#2583

Open
jbampton wants to merge 1 commit intoapache:mainfrom
jbampton:add-zizmor-hook
Open

security: pre-commit add zizmor static analysis for actions#2583
jbampton wants to merge 1 commit intoapache:mainfrom
jbampton:add-zizmor-hook

Conversation

@jbampton
Copy link
Member

https://zizmor.sh/

On the next ASF page under heading "Dangerous workflows" they recommend using zizmor

https://cwiki.apache.org/confluence/display/BUILDS/GitHub+Actions+Security

@github-actions github-actions bot added github_actions Pull requests that update GitHub Actions code yaml labels Feb 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code yaml

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants