Skip to content

chore(ci): Fix zizmor security findings in workflows#956

Open
morganchen12 wants to merge 1 commit into
mainfrom
mc/zizmor
Open

chore(ci): Fix zizmor security findings in workflows#956
morganchen12 wants to merge 1 commit into
mainfrom
mc/zizmor

Conversation

@morganchen12

Copy link
Copy Markdown

No description provided.

Resolved findings flagged by zizmor:
- Added explicit global `contents: read` permissions to `ci.yml`, `nightly.yml`, and `release.yml`.
- Configured checkouts to set `persist-credentials: false` in `ci.yml`, `nightly.yml`, and the staging phase of `release.yml`.
- Added explicit `persist-credentials: true` with a `# zizmor: ignore[artipacked]` comment to the checkout step in the publishing phase of `release.yml`, where credentials are required for git commands inside `publish_preflight_check.sh`.
@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant