Skip to content

Conversation

zimeg
Copy link
Member

@zimeg zimeg commented May 20, 2025

Summary

This PR uses the wonderful zizmor tool to audit our own workflows and pinact for pinned versioning 👾

Reviewers

A similar audit can be performed with the zizmor tool:

$ zizmor .
...
No findings to report. Good job! (2 suppressed)

The suppressed findings are expected permission blocks at the top-level of a workflow, but we set this for each job.

Requirements

@zimeg zimeg self-assigned this May 20, 2025
@zimeg zimeg added the tests M-T: Testing work only label May 20, 2025
@zimeg zimeg marked this pull request as draft May 20, 2025 01:57
@zimeg
Copy link
Member Author

zimeg commented May 20, 2025

🗣️ CI is failing for now due to unsupported ubuntu versions of the runner! Marking as a draft until further notice I hope the tests pass.

@zimeg zimeg marked this pull request as ready for review May 21, 2025 00:23
@zimeg
Copy link
Member Author

zimeg commented May 22, 2025

@WilliamBergamin Soon now we will have the efforts across workflows in @slackapi projects complete I'm so hoping. Thanks for the review!

@zimeg zimeg merged commit 6f65a3c into main May 22, 2025
8 checks passed
@zimeg zimeg deleted the ci-audit branch May 22, 2025 00:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tests M-T: Testing work only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants