Skip to content

Add zizmor and harden GitHub Actions workflows#49

Open
jeromekelleher wants to merge 1 commit into
tskit-dev:mainfrom
jeromekelleher:add-zizmor
Open

Add zizmor and harden GitHub Actions workflows#49
jeromekelleher wants to merge 1 commit into
tskit-dev:mainfrom
jeromekelleher:add-zizmor

Conversation

@jeromekelleher

Copy link
Copy Markdown
Member

Zizmor is a static analysis method for GitHub actions which mitigates against supply chain attacks (which are a real and scary thing). I think it would be good to apply this across the tskit-dev ecosystem so that we don't get packages hijacked (however unlikely that is).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant