lmstudio-ai / venvstacks

Virtual environment stacks for Python
http://venvstacks.lmstudio.ai/
MIT License
171 stars 5 forks source link

Scan GitHub workflows with zizmor #50

Closed ncoghlan closed 3 weeks ago

ncoghlan commented 3 weeks ago

Static security analysis tool for GitHub action configs: https://github.com/woodruffw/zizmor

(discovered via one of the other Python core developers running it on the CPython repo and reporting the results)

ncoghlan commented 3 weeks ago

51 addresses the initial scan result, but keeping this issue open as any change to the workflows should automatically re-run the scan and upload the SARIF results.

ncoghlan commented 3 weeks ago

51 has been updated to also include an automated scan (as per https://github.com/woodruffw/zizmor/issues/69)

ncoghlan commented 3 weeks ago

While #51 mostly implemented this CI feature, it can only be fully resolved once the repository has been published: