Skip to content

Harden GitHub Actions workflows: pinning, static analysis, enforcement #9033

Description

@Vaivaswat2244

Tracking issue for the GHA hardening work started in #8620 and #9032. Split out
from #8674.

#8620 hardened our workflows manually, but nothing enforces it — that's how
continuous-release.yml landed later with floating tags. This issue tracks closing
that gap.

Scope

To discuss

  • Static analysis in CI. @ulgens proposed zizmor (+ found it via pinact).
    Open questions: zizmor vs actionlint vs both, and CI step vs git hook. Worth
    its own thread below.

cc @limzykenneth @lirenjie95

Metadata

Metadata

Assignees

No one assigned

    Labels

    DevOpsImprovements to development process, including build, automations, and testingDiscussion

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions