Skip to content

ci: audit workflows with zizmor and fix its findings - #52

Merged
jo16oh merged 1 commit into
mainfrom
ci/zizmor
Sep 24, 2026
Merged

jo16oh merged 1 commit into
mainfrom
ci/zizmor

Conversation

@jo16oh

@jo16oh jo16oh commented Sep 24, 2026

Copy link
Copy Markdown
Owner
  • Run zizmor in CI and in the pre-commit hook
  • Default the workflow token to contents: read, and to no permissions in release.yml
  • Set persist-credentials: false on every checkout
  • Pass the token only to the step that pushes gh-pages, not to the vp install step before it
  • Turn off caching in the release workflow

@jo16oh jo16oh added the skip-changelog left out of the generated release notes label Sep 24, 2026
@jo16oh
jo16oh merged commit 54abb9a into main Sep 24, 2026
3 checks passed
@jo16oh
jo16oh deleted the ci/zizmor branch September 24, 2026 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog left out of the generated release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant