Skip to content

ci(security): eliminate workflow audit warnings - #279

Merged
jsugg merged 1 commit into
mainfrom
ci/eliminate-workflow-warnings
Jul 29, 2026
Merged

ci(security): eliminate workflow audit warnings#279
jsugg merged 1 commit into
mainfrom
ci/eliminate-workflow-warnings

Conversation

@jsugg

@jsugg jsugg commented Jul 29, 2026

Copy link
Copy Markdown
Owner

Summary

  • prevent checkout credential persistence
  • remove shell template-injection paths
  • scope workflow permissions to consuming jobs
  • replace workflow_run publication with explicit CI dispatch
  • make pinned zizmor validation blocking

Pages branch pushes use ephemeral authentication supplied through process environment rather than persisted Git credentials.

Verification

  • zizmor 1.28.0: zero findings
  • actionlint
  • workflow security regression tests
  • Pages state-branch unit and integration tests

Prevent checkout tokens and untrusted workflow context from reaching persistent Git configuration or shell command text.\n\nScope permissions per job, publish Pages through explicit dispatch, and make pinned offline zizmor findings blocking.
@jsugg
jsugg merged commit a6624da into main Jul 29, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant