Skip to content

fix: harden GitHub Actions workflows#98

Open
reberhardt7 wants to merge 1 commit intomainfrom
fix/zizmor-workflow-security
Open

fix: harden GitHub Actions workflows#98
reberhardt7 wants to merge 1 commit intomainfrom
fix/zizmor-workflow-security

Conversation

@reberhardt7
Copy link

@reberhardt7 reberhardt7 commented Mar 25, 2026

Summary

  • Fix pnpm/action-setup SHA to match v5 tag across all 12 workflow files (resolves ref-version-mismatch findings)
  • Add Dependabot cooldown configuration (7-day default) via zizmor auto-fix
  • Disable secrets-outside-env rule in .github/zizmor.yml
  • Update stale cache-poisoning ignore line numbers in .github/zizmor.yml

- Fix pnpm/action-setup SHA to match v5 tag (58e6119 -> fc06bc1) across
  all 12 workflow files (ref-version-mismatch)
- Add Dependabot cooldown configuration (7-day default)
- Disable secrets-outside-env rule in .github/zizmor.yml
- Update cache-poisoning ignore line numbers in .github/zizmor.yml

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@socket-security
Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedgithub/​pnpm/​action-setup@​fc06bc1257f339d1d5d8b3a19a8cae5388b5532098100100100100

View full report

@socket-security-staging
Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedgithub/​pnpm/​action-setup@​fc06bc1257f339d1d5d8b3a19a8cae5388b5532098100100100100

View full report

@reberhardt7 reberhardt7 changed the title fix: harden GitHub Actions workflows (zizmor) fix: harden GitHub Actions workflows Mar 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant