build: Add zizmor workflow and harden CI/CD a bit
#162
background
wait
wait-all
cancel
Loading