Skip to content

ci: add zizmor - #188

Merged
PierreJeanjacquot merged 2 commits into
mainfrom
ci/zizmor
Oct 6, 2026
Merged

PierreJeanjacquot merged 2 commits into
mainfrom
ci/zizmor

Conversation

@PierreJeanjacquot

@PierreJeanjacquot PierreJeanjacquot commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

run zizmor with the default profile on workflows, both locally and in CI by running mise verify-all.

currently ignored finding:

  • use-trusted-publishing on .github/workflows/rust-build.yml : the workflow don't use trusted publishing for now, in the other hand publishing is not used by internal consumers. Wont fix until publishing is needed.

@PierreJeanjacquot
PierreJeanjacquot force-pushed the ci/zizmor branch 2 times, most recently from 04bf3dc to faa340d Compare October 5, 2026 15:25
@PierreJeanjacquot
PierreJeanjacquot force-pushed the ci/zizmor branch 3 times, most recently from 26eeb53 to e1ad492 Compare October 6, 2026 13:53
This is a real finding that deserve to be addressed, postponed for now as consumers repo currently don't use `publish-crates-io: true`
@PierreJeanjacquot
PierreJeanjacquot merged commit 76592f3 into main Oct 6, 2026
4 checks passed
@PierreJeanjacquot
PierreJeanjacquot deleted the ci/zizmor branch October 6, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants