Skip to content

chore(ci): harden GitHub Actions workflows#532

Open
geoquant wants to merge 1 commit into
cloudflare:mainfrom
geoquant:geoquant/zizmor-hardening
Open

chore(ci): harden GitHub Actions workflows#532
geoquant wants to merge 1 commit into
cloudflare:mainfrom
geoquant:geoquant/zizmor-hardening

Conversation

@geoquant
Copy link
Copy Markdown
Collaborator

@geoquant geoquant commented May 22, 2026

Summary

Hardens GitHub Actions workflows for zizmor by pinning third-party actions, reducing default permissions, disabling checkout credential persistence, and avoiding direct expression interpolation in shell scripts.

zizmor is a static analysis tool for finding security issues in GitHub Actions workflows.

Testing

Not run; workflow-only changes.

  • Reviews
  • bonk has reviewed the change
  • automated review not possible because: workflow security hardening requires human review
  • Tests
  • Tests included/updated
  • Automated tests not possible - manual testing has been completed as follows: reviewed workflow diffs and permissions
  • Additional testing not necessary because: n/a

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new Bot commented May 22, 2026

npm i https://pkg.pr.new/@cloudflare/kumo@532

commit: be8338f

@github-actions
Copy link
Copy Markdown
Contributor

Docs Preview

View docs preview

Commit: be8338f

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant