Skip to content

chore(ci): resolve zizmor security analysis findings in GitHub Actions - #3970

Open
westarle wants to merge 1 commit into
googleapis:mainfrom
westarle:zizmor-minimal
Open

chore(ci): resolve zizmor security analysis findings in GitHub Actions#3970
westarle wants to merge 1 commit into
googleapis:mainfrom
westarle:zizmor-minimal

Conversation

@westarle

@westarle westarle commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
  • Pin GitHub Actions to exact SHA digests across all workflows
  • Set persist-credentials: false on actions/checkout steps
  • Add explicit permissions block to update-apis.yaml

@westarle
westarle requested a review from a team as a code owner August 5, 2026 11:55
@generated-files-bot

Copy link
Copy Markdown

Warning: This pull request is touching the following templated files:

  • .github/workflows/ci.yaml - .github/workflows/ci.yaml (GitHub Actions) should be updated in synthtool

@product-auto-label product-auto-label Bot added the size: s Pull request size is small. label Aug 5, 2026
@westarle westarle added the owlbot:run Add this label to trigger the Owlbot post processor. label Aug 5, 2026
- Pin GitHub Actions to exact SHA digests across all workflows
- Set persist-credentials: false on actions/checkout steps
- Add explicit permissions block to update-apis.yaml
@gcf-owl-bot gcf-owl-bot Bot removed the owlbot:run Add this label to trigger the Owlbot post processor. label Aug 5, 2026
@westarle westarle added the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Aug 5, 2026
@yoshi-kokoro yoshi-kokoro removed the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Aug 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size: s Pull request size is small.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants