Skip to content

Remediates weaknesses in CI, as advised by zizmor#6578

Open
DougReeder wants to merge 1 commit intoHubs-Foundation:masterfrom
DougReeder:zizmor
Open

Remediates weaknesses in CI, as advised by zizmor#6578
DougReeder wants to merge 1 commit intoHubs-Foundation:masterfrom
DougReeder:zizmor

Conversation

@DougReeder
Copy link
Copy Markdown
Member

@DougReeder DougReeder commented Apr 28, 2026

What?

Remediates weaknesses in CI, as advised by zizmor
Addresses Hubs-Foundation/.github#5 for the hubs client repo

Why?

Supply-chain attacks must be taken seriously

Examples

no change in CI functionality

How to test

Exercise each GitHub job

To see the audit, run the zizmor static analysis tool

Documentation of functionality

n/a

Limitations

This sets up the GitHub security monitor. After several runs, the output should tell us the needed permissions.
Another PR will have to set those.

Alternative implementations considered

These are best practice, but we need to determine what the continuing costs of using them are.

Open questions

None.

Additional details or related context

Context: https://arstechnica.com/security/2026/04/open-source-package-with-1-million-monthly-downloads-stole-user-credentials/

@DougReeder DougReeder requested a review from Exairnous April 28, 2026 03:14
@DougReeder DougReeder force-pushed the zizmor branch 3 times, most recently from 4197400 to 2a33135 Compare April 29, 2026 03:06
Why: Supply-chain attacks must be taken seriously
@DougReeder
Copy link
Copy Markdown
Member Author

Latest force-push addresses the issues raised in the dev meetup

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant