[FEA]: Add static analysis checks for our GHA workflows
Open
infra
- Dominant language
- C++
- Stars
- 2.5k
- Forks
- 486
- Avg merge
- 2d 6h
- Merged PRs (30d)
- 295
Description
### Is this a duplicate?
- [x] I confirmed there appear to be no [duplicate issues](https://github.com/NVIDIA/cccl/issues) for this request and that I agree to the [Code of Conduct](CODE_OF_CONDUCT.md)
### Area
Infrastructure
### Is your feature request related to a problem? Please describe.
There are static analysis tools available to scan for errors / security issues in GHA workflows and actions:
- https://github.com/zizmorcore/zizmor
- https://github.com/rhysd/actionlint/
We aren't using these.
### Describe the solution you'd like
We should use these.
### Describe alternatives you've considered
_No response_
### Additional context
_No response_
Contributor guide
Assessment
This issue has not been assessed yet.