Skip to content

Update zizmor; switch to hash-pinned GitHub Actions - #7888

Open
legoktm wants to merge 4 commits into
developfrom
hashed-actions
Open

Update zizmor; switch to hash-pinned GitHub Actions#7888
legoktm wants to merge 4 commits into
developfrom
hashed-actions

Conversation

@legoktm

@legoktm legoktm commented Jul 15, 2026

Copy link
Copy Markdown
Member

See commit messages for specific details.

Test plan

  • CI workflows pass

Checklist

This change accounts for:

  • any required additional documentation
  • any necessary AppArmor changes (added or removed application files)
  • any impact on new SecureDrop installs and upgrades
  • our dependency update policy

@legoktm
legoktm requested a review from a team as a code owner July 15, 2026 21:13
@legoktm legoktm moved this to Ready For Review in SecureDrop Jul 15, 2026
@nathandyer nathandyer moved this from Ready For Review to In Progress in SecureDrop Jul 21, 2026
This lint is primarily for publish workflows that could use a poisoned
cache for release artifacts, but our cargo-vet workflow isn't that sensitive
so keeping the caching is worth it.
Done using `GH_TOKEN=$(gh auth token) zizmor . --fix=all`.
@legoktm legoktm moved this from In Progress to Ready For Review in SecureDrop Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Ready For Review

Development

Successfully merging this pull request may close these issues.

3 participants