Skip to content

Add zizmor security analysis + dependabot cooldown#51

Merged
Seldaek merged 2 commits into
mainfrom
add-zizmor-dependabot
May 29, 2026
Merged

Add zizmor security analysis + dependabot cooldown#51
Seldaek merged 2 commits into
mainfrom
add-zizmor-dependabot

Conversation

@Seldaek

@Seldaek Seldaek commented May 28, 2026

Copy link
Copy Markdown
Member

Adds a zizmor GitHub Actions security-analysis workflow (matching composer/packagist) and a 7-day cooldown on the github-actions dependabot config, and hardens the existing workflows so zizmor (pedantic) passes (actions pinned to commit SHAs, concurrency limits, persist-credentials: false on read-only checkouts).

Seldaek added 2 commits May 28, 2026 23:45
Pin actions to commit SHAs (latest releases), add concurrency limits, and set persist-credentials: false on read-only checkouts.
@Seldaek Seldaek merged commit 2ea3213 into main May 29, 2026
23 checks passed
@Seldaek Seldaek deleted the add-zizmor-dependabot branch May 29, 2026 09:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant