Skip to content

ci: add zizmor workflow#134

Merged
LadyBluenotes merged 3 commits into
TanStack:mainfrom
Sheraff:ci/add-zizmor
May 12, 2026
Merged

ci: add zizmor workflow#134
LadyBluenotes merged 3 commits into
TanStack:mainfrom
Sheraff:ci/add-zizmor

Conversation

@Sheraff
Copy link
Copy Markdown
Contributor

@Sheraff Sheraff commented May 12, 2026

Summary

  • Add a pinned zizmor GitHub Actions security analysis workflow.
  • Harden existing workflows by pinning external actions, disabling checkout credential persistence, and scoping write permissions to the release job.
  • Move dynamic GitHub expressions out of shell commands and use an explicit token-authenticated release push URL.

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new Bot commented May 12, 2026

Open in StackBlitz

npm i https://pkg.pr.new/@tanstack/intent@134

commit: e7d78d9

Comment thread .github/workflows/benchmarks.yml Outdated
@LadyBluenotes LadyBluenotes merged commit 915f584 into TanStack:main May 12, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants