ci: add zizmor workflow for automated GitHub Actions auditing - #8
Merged
Merged
Conversation
added 2 commits
September 16, 2026 12:11
- Introduce a new Zizmor audit workflow to statically analyze all GitHub Actions for security vulnerabilities. - Update checkout action comments to reflect the exact v7.0.1 tag for clarity. - Document the new workflow in the CHANGELOG.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Hardening: Zizmor Actions Audit
Introduces automated, deterministic security scanning for our GitHub Actions workflows using Zizmor.
What changed and why
Zizmor Audit Workflow (
zizmor.yml)Added a new GitHub Actions workflow that statically analyzes all our workflows for security vulnerabilities (e.g., untrusted checkouts, malicious code execution via workflow inputs, missing permissions).
zizmorcore/zizmor-actionto maintain supply-chain integrity.Strict File Permissions & Tag Refinement
permissions: contents: readtophpstan.ymlandrun-tests.ymlto adhere to the principle of least privilege.persist-credentials: falseonactions/checkoutsteps to prevent Git credentials from persisting in the job workspace and potentially being exfiltrated.actions/checkoutSHAs to reflect the exact target tag (v7.0.1), avoiding confusion while retaining the security of SHA pinning.Checklist
persist-credentials: false)