Skip to content

Configure zizmor to check the action.yml/workflow files and address any issues#30

Merged
glaubinix merged 12 commits intomainfrom
zizmor-fixes
Apr 21, 2026
Merged

Configure zizmor to check the action.yml/workflow files and address any issues#30
glaubinix merged 12 commits intomainfrom
zizmor-fixes

Conversation

@glaubinix
Copy link
Copy Markdown
Member

This mainly fixes various potential code injection via template expansion in places where ${{ github.event.client_payload... }}" is used.

You can validate the changes by adjusting the Conductor action in your GH workflow file.

            - name: "Running Conductor"
              uses: packagist/conductor-github-action@zizmor-fixes

@glaubinix glaubinix self-assigned this Apr 21, 2026
@glaubinix glaubinix requested a review from a team April 21, 2026 13:07
@IgorBenko IgorBenko self-requested a review April 21, 2026 13:09
Comment thread action.yml Outdated
Copy link
Copy Markdown
Contributor

@pscheit pscheit left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

oki just a few style nitpicks :) looks good though

Comment thread action.yml Outdated
Comment thread action.yml Outdated
@glaubinix glaubinix requested a review from pscheit April 21, 2026 14:16
Copy link
Copy Markdown
Contributor

@IgorBenko IgorBenko left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice, thanks 👍 Just a small typo

Comment thread action.yml Outdated
Co-authored-by: Igor Benko <igor.benko@gmail.com>
@glaubinix glaubinix merged commit 744286c into main Apr 21, 2026
1 check passed
@glaubinix glaubinix deleted the zizmor-fixes branch April 21, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants