Skip to content

Use zizmor to audit github actions #638

Open
@notmandatory

Description

@notmandatory

Describe the enhancement

We should audit github actions to make sure an attacker can't publish compromised bdk-ffi binaries.

see: https://discord.com/channels/753336465005608961/754077749282471937/1317184034010435625

Use case

See documentation for zizmor.

Additional context

See: bitcoindevkit/bdk#1775.

Metadata

Metadata

Assignees

No one assigned

    Labels

    CIContinuous integration pipeline related

    Type

    No type

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions