Skip to content

fix: add zizmor and remediate all findings#871

Merged
rapids-bot[bot] merged 8 commits intorapidsai:mainfrom
gforsyth:securitize
Apr 27, 2026
Merged

fix: add zizmor and remediate all findings#871
rapids-bot[bot] merged 8 commits intorapidsai:mainfrom
gforsyth:securitize

Conversation

@gforsyth
Copy link
Copy Markdown
Contributor

@gforsyth gforsyth commented Apr 24, 2026

Changes

  • all upstream actions are pinned to SHAs (with versions in comments, so renovate still works

  • all permissions are explicitly set now, and we don't persist credentials

  • all inputs are sanitized -- this is done by moving inputs to env-variables and referencing those

  • added zizmor to pre-commit so these fixes stay in place

  • fix(ci): pin all third-party actions and workflows

  • fix: artipacked credential fixes

  • fix: remove template injection sites

  • fix: explicitly request all needed permissions

  • fix: ignore secrets-inherit where we want inherited secrets

  • fix: ignore dangerous-triggers for breaking change alert

  • fix: mark cache-poisoning warning as a non-issue

  • feat: add zizmor pre-commit hook

@gforsyth
Copy link
Copy Markdown
Contributor Author

/merge

@rapids-bot rapids-bot Bot merged commit 1c18178 into rapidsai:main Apr 27, 2026
127 of 129 checks passed
@gforsyth gforsyth deleted the securitize branch April 27, 2026 15:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants