Skip to content

ci: use zizmor to prevent supply chain attacks via GHA#1518

Merged
jedisct1 merged 1 commit intojedisct1:masterfrom
tob-scott-a:workflows
Mar 8, 2026
Merged

ci: use zizmor to prevent supply chain attacks via GHA#1518
jedisct1 merged 1 commit intojedisct1:masterfrom
tob-scott-a:workflows

Conversation

@tob-scott-a
Copy link
Contributor

No description provided.

@jedisct1
Copy link
Owner

jedisct1 commented Mar 7, 2026

GitHub actions don't publish anything, so the impact of a supply chain attack would be quite limited.

The dotnet-core.yml workflow builds .NET packages, though, so pinning the actions hashes can be a good thing, thanks!

@jedisct1 jedisct1 merged commit 678c8f3 into jedisct1:master Mar 8, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants