Skip to content

fix(ci): add zizmor security linter for github actions - #3358

Merged
lukekarrys merged 1 commit into
nodejs:mainfrom
cclauss:zizmor
Aug 25, 2026
Merged

fix(ci): add zizmor security linter for github actions#3358
lukekarrys merged 1 commit into
nodejs:mainfrom
cclauss:zizmor

Conversation

@cclauss

@cclauss cclauss commented Aug 14, 2026

Copy link
Copy Markdown
Contributor
Checklist
  • npm install && npm run lint && npm test passes
  • tests are included
  • documentation is changed or added
  • commit message follows commit guidelines
Description of change

https://docs.zizmor.sh -- zizmor is a static analysis tool that can find and fix security issues in common CI/CD setups, including GitHub Actions, Dependabot, and pre-commit.

Fixes:

After this is merged, if someone has confidence and experience dealing with excessive-permissions, remove the zizmor.yml file and fix all remaining zizmor issues.

I have made regrettable errors trying to fix excessive-permissions, so I am reluctant to fix them in this pull request, which does other useful things.

The Lint Python failure is fixed in:

@lukekarrys
lukekarrys merged commit 8466166 into nodejs:main Aug 25, 2026
37 of 38 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants