**Describe the enhancement** We should audit github actions to make sure an attacker can't publish compromised bdk-ffi binaries. see: https://discord.com/channels/753336465005608961/754077749282471937/1317184034010435625 **Use case** See documentation for [zizmor](https://woodruffw.github.io/zizmor/). **Additional context** This auditing should also be done on other bitcoindevkit org repos. In particular bdk-ffi, see: bitcoindevkit/bdk-ffi#638.