Skip to content

Update to Zizmor 1.23.1#579

Open
caxu-rh wants to merge 4 commits intoredhat-certification:mainfrom
caxu-rh:update-fix-zizmor
Open

Update to Zizmor 1.23.1#579
caxu-rh wants to merge 4 commits intoredhat-certification:mainfrom
caxu-rh:update-fix-zizmor

Conversation

@caxu-rh
Copy link
Contributor

@caxu-rh caxu-rh commented Mar 17, 2026

  • Update to Zizmor version 1.23.1
  • Fix/ignore identified issues
    • Pin actions/setup-python usage
    • Increase Dependabot timeout to 7 days (adjustment in Zizmor audit rule)
    • Disable secrets-outside-env check in Zizmor (it could be nice to use GitHub Environments to further control access to workflow secrets but for now this is just noise)

caxu-rh added 4 commits March 17, 2026 15:17
Signed-off-by: Caleb Xu <caxu@redhat.com>
Signed-off-by: Caleb Xu <caxu@redhat.com>
Signed-off-by: Caleb Xu <caxu@redhat.com>
Signed-off-by: Caleb Xu <caxu@redhat.com>
@github-actions
Copy link

Thanks for your pull request!

A maintainer will review this pull request and trigger functional testing by adding the ok-to-test label.

This comment was auto-generated by GitHub Actions.

@mgoerens mgoerens added the ok-to-test Used after code review to run E2E/integration tests. label Mar 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Used after code review to run E2E/integration tests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants