Summary
The new weekly zizmor audit (#218) currently reports 25 findings across our GitHub Actions workflows. Since the workflow doesn't auto-fix (by design, remediation is a human decision), this issue tracks reviewing and fixing them.
Live findings: https://github.com/Chaste/Chaste.github.io/security/code-scanning?query=is%3Aopen
Current breakdown (25 findings)
By rule:
unpinned-uses (16) — actions referenced by tag (e.g. @v4) rather than pinned to a commit SHA
artipacked (5) — actions/checkout steps that don't set persist-credentials: false
excessive-permissions (4) — jobs/workflows without explicit minimal permissions
By file:
deploy.yaml (9)
check-links-pr.yaml (5)
check-links-schedule.yaml (4)
zizmor-schedule.yaml (4)
build.yaml (3)
Summary
The new weekly zizmor audit (#218) currently reports 25 findings across our GitHub Actions workflows. Since the workflow doesn't auto-fix (by design, remediation is a human decision), this issue tracks reviewing and fixing them.
Live findings: https://github.com/Chaste/Chaste.github.io/security/code-scanning?query=is%3Aopen
Current breakdown (25 findings)
By rule:
unpinned-uses(16) — actions referenced by tag (e.g.@v4) rather than pinned to a commit SHAartipacked(5) —actions/checkoutsteps that don't setpersist-credentials: falseexcessive-permissions(4) — jobs/workflows without explicit minimalpermissionsBy file:
deploy.yaml(9)check-links-pr.yaml(5)check-links-schedule.yaml(4)zizmor-schedule.yaml(4)build.yaml(3)