new feature: use zizmor to static analysis the GitHub Actions files and fix them
- Dominant language
- Rust
- Stars
- 5.4k
- Forks
- 825
- Avg merge
- 1d 14m
- Merged PRs (30d)
- 127
Description
### Feature Description
zizmor: https://woodruffw.github.io/zizmor/
As more and more attackers using GitHub Actions to steal the token or attack other users such as `Mining Scripts`
more can check issue one-api or https://www.praetorian.com/blog/compromising-bytedances-rspack-github-actions-vulnerabilities/
we can use static check to avoid them as we can.
### Problem and Solution
using zizmor to fix all
### Additional Context
_No response_
### Are you willing to contribute to the development of this feature?
- [ ] Yes, I am willing to contribute to the development of this feature.
Contributor guide
Research direction
Start by running zizmor against the repository's GitHub Actions files and review the reported findings. Inventory the workflows affected and use the zizmor results to define completion; done means the identified issues are fixed across the workflows.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100