Skip to content

Resolve remaining zizmor findings in our workflows - #420

Merged
eXpl0it3r merged 1 commit into
masterfrom
feature/workflow-hardening
Oct 4, 2026
Merged

eXpl0it3r merged 1 commit into
masterfrom
feature/workflow-hardening

Conversation

@eXpl0it3r

@eXpl0it3r eXpl0it3r commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Description

Follow-up to #418, which didn't catch everything zizmor complains about. With this PR zizmor --pedantic comes back clean for all three workflows, except for the container images and actions referenced by tag instead of digest, which is on purpose.

  • ci.yml: Matrix values are passed to the run steps through env instead of being expanded into the script
  • release.yml: Uses bash as default shell and $GITHUB_WORKSPACE instead of ${{ github.workspace }} inside run
  • release.yml: Drops the MinGW cache, as a release build shouldn't restore something an untrusted run could've written into the cache, the toolchain is now downloaded on every run

Note that the Windows build steps of the release workflow now run in bash instead of PowerShell, the steps that explicitly use pwsh stay as they are.

How to test this PR?

CI should succeed.

The release and NuGet workflows don't run for PRs, so they should be checked with a manual run on this branch.

- Pass matrix values and the workspace path to run steps through env
- Use bash as default shell for the release builds
- Drop the MinGW cache from the release builds to avoid cache poisoning
@eXpl0it3r
eXpl0it3r force-pushed the feature/workflow-hardening branch from 3276fd7 to d16ac52 Compare October 4, 2026 15:04
@eXpl0it3r
eXpl0it3r merged commit 58d0990 into master Oct 4, 2026
54 checks passed
@eXpl0it3r
eXpl0it3r deleted the feature/workflow-hardening branch October 4, 2026 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant