Skip to content

Investigate GitHub Action static analysis tool #2317

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
ribose-jeffreylau opened this issue Mar 5, 2025 · 0 comments
Open

Investigate GitHub Action static analysis tool #2317

ribose-jeffreylau opened this issue Mar 5, 2025 · 0 comments
Labels
continuous integration Any issues pertaining to CI, e.g. GHA security

Comments

@ribose-jeffreylau
Copy link
Contributor

Context

A write-up on how supply chain attack on Ultralytics occurred, using insecure GHA: https://blog.yossarian.net/2024/12/06/zizmor-ultralytics-injection

Candidate: zizmor

zizmor is a static analysis tool for GitHub Actions.

How integration with GHA can be done: https://woodruffw.github.io/zizmor/usage/#use-in-github-actions

@ribose-jeffreylau ribose-jeffreylau added continuous integration Any issues pertaining to CI, e.g. GHA security labels Mar 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
continuous integration Any issues pertaining to CI, e.g. GHA security
Projects
None yet
Development

No branches or pull requests

1 participant