Skip to content

Add zizmor security scanning and improve CI/CD security#315

Open
jfantinhardesty wants to merge 2 commits intoSeagate:developfrom
jfantinhardesty:feature/add-zizmor
Open

Add zizmor security scanning and improve CI/CD security#315
jfantinhardesty wants to merge 2 commits intoSeagate:developfrom
jfantinhardesty:feature/add-zizmor

Conversation

@jfantinhardesty
Copy link
Copy Markdown

This PR adds Zizmor to the CI/CD pipeline. Zizmor is a tool that scans GitHub Actions and then finds security issues with the way they are setup. We have been using it in our cloudfuse project for a few months and found it very useful. This can help prevent compromises to released packages, etc. that have been becoming very common in the past few months.

I also took a stab at trying to apply fixes for the issues it identified. There are likely a few issues here than can only be identified when running the CI/CD pipelines. Hoping we can have a bit of a back and forth to fix any issues with the runs.

…CI/CD security

Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>
Signed-off-by: James Fantin-Hardesty <24646452+jfantinhardesty@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant