-
Notifications
You must be signed in to change notification settings - Fork 16
Open
Description
zizmor is a GH actions audit tool, I'm hoping it works on actual actions yml as well (and not just workflow files): this would be very useful for the tuf-on-ci actions...
- see workflows: address zizmor findings sigstore/root-signing#1397
- some actions in this repo do use the git credentials so need to be careful WRT
persist-credentials
Metadata
Metadata
Assignees
Labels
No labels