Skip to content

Add zizmor security analysis + dependabot cooldown#165

Merged
johnstevenson merged 2 commits into
mainfrom
add-zizmor-dependabot
May 29, 2026
Merged

Add zizmor security analysis + dependabot cooldown#165
johnstevenson merged 2 commits into
mainfrom
add-zizmor-dependabot

Conversation

@Seldaek
Copy link
Copy Markdown
Member

@Seldaek Seldaek commented May 28, 2026

Adds a zizmor GitHub Actions security-analysis workflow (matching composer/packagist) and a 7-day cooldown on the github-actions dependabot config, and hardens the existing workflows so zizmor (pedantic) passes (actions pinned to commit SHAs, concurrency limits, persist-credentials: false on read-only checkouts).

Seldaek added 2 commits May 28, 2026 23:42
Pin actions to commit SHAs (latest releases), add concurrency limits, and set persist-credentials: false on read-only checkouts.
@johnstevenson johnstevenson merged commit 6a7dcec into main May 29, 2026
39 checks passed
@johnstevenson
Copy link
Copy Markdown
Member

Cool.

@Seldaek Seldaek deleted the add-zizmor-dependabot branch May 29, 2026 13:39
@Seldaek
Copy link
Copy Markdown
Member Author

Seldaek commented May 29, 2026

@johnstevenson might be good to delete 1.0/2.0 branches too as these are not updated, but they seem kinda EOL at this point

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants