Skip to content
This repository was archived by the owner on Jun 7, 2026. It is now read-only.

ci: tighten zizmor actions hardening#88

Merged
djchen merged 1 commit into
mainfrom
ci/zizmor-hardening
May 26, 2026
Merged

ci: tighten zizmor actions hardening#88
djchen merged 1 commit into
mainfrom
ci/zizmor-hardening

Conversation

@djchen

@djchen djchen commented May 26, 2026

Copy link
Copy Markdown
Owner

Summary

  • expand zizmor coverage to all of .github and fail on low+ findings
  • deny default workflow token permissions and scope contents:read to checkout jobs
  • add zizmor allowed-action policy, CI concurrency, and Dependabot cooldowns that satisfy zizmor

Verification

  • docker run --rm -v "/home/djchen/Workspace/opencode-web-docker:/workspace:ro" -w /workspace ghcr.io/zizmorcore/zizmor:latest --persona=regular --min-severity=low --min-confidence=medium .github
  • docker run --rm -v "/home/djchen/Workspace/opencode-web-docker:/repo:ro" -w /repo rhysd/actionlint:latest
  • git diff --check

@djchen djchen merged commit e20d787 into main May 26, 2026
5 checks passed
@djchen djchen deleted the ci/zizmor-hardening branch May 26, 2026 02:02
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant