Skip to content

[ci] enforce zizmor checks, drop codecov#346

Open
jameslamb wants to merge 2 commits intomainfrom
ci/security
Open

[ci] enforce zizmor checks, drop codecov#346
jameslamb wants to merge 2 commits intomainfrom
ci/security

Conversation

@jameslamb
Copy link
Copy Markdown
Collaborator

Proposing a couple of security-related changes:

  • dropping codecov
  • enforcing zizmor checks (GitHub Actions pinned to SHAs, protections against script injection, limiting permissions, etc.)

Notes for Reviewers

Also proposing doing the following manual steps after this is merged:

  • remove codecov integration from the repo
  • set an allowlist of GitHub Actions third-party workflows

@jameslamb jameslamb requested a review from bburns632 April 9, 2026 03:14
@jameslamb jameslamb added the ci label Apr 9, 2026
@jameslamb jameslamb marked this pull request as ready for review April 9, 2026 03:17
@jameslamb jameslamb requested a review from jayqi April 9, 2026 03:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant