apache / apache/opendal

new feature: use zizmor to static analysis the GitHub Actions files and fix them

Open
#5,502 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Rust
Stars
5.4k
Forks
825
Avg merge
1d 14m
Merged PRs (30d)
127

Description

### Feature Description

zizmor: https://woodruffw.github.io/zizmor/

As more and more attackers using GitHub Actions to steal the token or attack other users such as `Mining Scripts`
more can check issue one-api or https://www.praetorian.com/blog/compromising-bytedances-rspack-github-actions-vulnerabilities/
we can use static check to avoid them as we can.

### Problem and Solution

using zizmor to fix all

### Additional Context

_No response_

### Are you willing to contribute to the development of this feature?

- [ ] Yes, I am willing to contribute to the development of this feature.

Contributor guide

Open the contributing guide

Research direction

Start by running zizmor against the repository's GitHub Actions files and review the reported findings. Inventory the workflows affected and use the zizmor results to define completion; done means the identified issues are fixed across the workflows.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.