Skip to content

Conversation

@adamtheturtle
Copy link
Member

@adamtheturtle adamtheturtle commented Dec 29, 2025

Add zizmor to dev dependencies and pre-commit config for GitHub Actions workflow security linting.

Changes

  • Add zizmor==1.19.0 to dev dependencies in pyproject.toml
  • Add zizmor pre-commit hook (runs on YAML files in .github directory)
  • Add zizmor to ci.skip list (where applicable)

Note

Introduces GitHub Actions security linting and minor workflow hardening.

  • Add zizmor==1.19.0 to dev deps in pyproject.toml and include zizmor.yml (also added to check-manifest ignore)
  • New pre-commit hook zizmor targeting YAML in .github and added to ci.skip
  • Harden workflows: set permissions: {} in CI and persist-credentials: false for actions/checkout@v6 in ci.yml, publish-site.yml, and release.yml

Written by Cursor Bugbot for commit 61cd651. This will update automatically on new commits. Configure here.

@adamtheturtle adamtheturtle merged commit c183367 into main Dec 29, 2025
6 checks passed
@adamtheturtle adamtheturtle deleted the add-zizmor branch December 29, 2025 17:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants