Skip to content

fix(ci): add zizmor security linter for github actions - #3358

Open
cclauss wants to merge 1 commit into
nodejs:mainfrom
cclauss:zizmor
Open

fix(ci): add zizmor security linter for github actions#3358
cclauss wants to merge 1 commit into
nodejs:mainfrom
cclauss:zizmor

Conversation

@cclauss

@cclauss cclauss commented Aug 14, 2026

Copy link
Copy Markdown
Contributor
Checklist
  • npm install && npm run lint && npm test passes
  • tests are included
  • documentation is changed or added
  • commit message follows commit guidelines
Description of change

https://docs.zizmor.sh -- zizmor is a static analysis tool that can find and fix security issues in common CI/CD setups, including GitHub Actions, Dependabot, and pre-commit.

Fixes:

After this is merged, if someone has confidence and experience dealing with excessive-permissions, remove the zizmor.yml file and fix all remaining zizmor issues.

I have made regrettable errors trying to fix excessive-permissions, so I am reluctant to fix them in this pull request, which does other useful things.

The Lint Python failure is fixed in:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant