Skip to content

ci: harden workflows against zizmor audit - #1

Merged
DiogoKaster merged 4 commits into
mainfrom
ci/harden-workflows-zizmor
Oct 7, 2026
Merged

DiogoKaster merged 4 commits into
mainfrom
ci/harden-workflows-zizmor

Conversation

@gvieira18

Copy link
Copy Markdown
Member

Summary

  • Pin every action to a commit SHA at its latest release (checkout v7.0.1, setup-node v7.0.0, release-please-action v5.0.0).
  • Scope permissions per job with explanatory comments; workflows default to permissions: {}.
  • Add concurrency, the ready_for_review trigger and the draft skip, aligned with heartdevs.com.
  • Replace the ad hoc npm install -g with a locked package.json pinning Claude Code, run via per-item validate:* scripts.
  • Read the Node version from .nvmrc (24) and cache npm explicitly.
  • Add Dependabot for github-actions with a 7-day cooldown.

uvx zizmor --persona=auditor . reports no findings.

@gvieira18
gvieira18 requested a review from a team October 6, 2026 22:37
@gvieira18
gvieira18 requested a review from DiogoKaster as a code owner October 6, 2026 22:37
@gvieira18 gvieira18 self-assigned this Oct 6, 2026
@DiogoKaster
DiogoKaster merged commit bd6360f into main Oct 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants