Skip to content

chore: Fix zizmor security issues in GHA workflows#4259

Open
alexandear wants to merge 1 commit into
google:masterfrom
alexandear-org:chore/fix-zizmor-gha
Open

chore: Fix zizmor security issues in GHA workflows#4259
alexandear wants to merge 1 commit into
google:masterfrom
alexandear-org:chore/fix-zizmor-gha

Conversation

@alexandear
Copy link
Copy Markdown
Contributor

This PR improves the security of our GitHub Actions workflows.

I use zizmor to detect issues.

Changes:

  • Add persist-credentials: false to all actions/checkout steps to prevent credential leakage.
  • Add cooldown: default-days: 7 to all Dependabot update entries to reduce PR noise.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant