Skip to content

Conversation

@ndimiduk
Copy link
Member

ASF Infrastructure recommends running zizmor static analysis on GitHub Actions workflows to detect security issues (see https://cwiki.apache.org/confluence/display/BUILDS/GitHub+Actions+Security).

@ndimiduk
Copy link
Member Author

Heya @gmcdonald should we add zizmor to the list of authorized actions? Seems kinda silly that this is the prescribed tool.

The action zizmorcore/zizmor-action@0dce2577a4760a2749d8cfb7a84b7d5585ebcb7d is not allowed in apache/hbase because all actions must be from a repository owned by your enterprise, created by GitHub, verified in the GitHub Marketplace, or match one of the patterns: ...

@ndimiduk ndimiduk force-pushed the 29893-zizmor-master branch 4 times, most recently from 5371b93 to e42dbee Compare February 12, 2026 14:01
@ndimiduk ndimiduk marked this pull request as ready for review February 12, 2026 14:02
@ndimiduk ndimiduk requested a review from Apache9 February 12, 2026 14:02
@ndimiduk ndimiduk force-pushed the 29893-zizmor-master branch from e42dbee to 4b8819f Compare February 12, 2026 14:14
@ndimiduk ndimiduk force-pushed the 29893-zizmor-master branch from 4b8819f to 31fa0b0 Compare February 12, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant