guacsec / guac

GUAC aggregates software security metadata into a high fidelity graph database.
https://guac.sh
Apache License 2.0
1.29k stars 176 forks source link

Fix zizmor audits #2276

Closed funnelfiasco closed 6 days ago

funnelfiasco commented 2 weeks ago

Address most of the zizmor audits (except scorecard, which has an open question with the Scorecard project)

Fixes #2269 Fixes #2270 Fixes #2271 Fixes #2272 Fixes #2274

(Opened as a single PR because several of them involve changes to the new zizmor.yml file)

PR Checklist