Skip to content

Use zizmor to audit github actions #1775

@notmandatory

Description

@notmandatory

Describe the enhancement

We should audit github actions to make sure an attacker can't publish compromised bdk-ffi binaries.

see: https://discord.com/channels/753336465005608961/754077749282471937/1317184034010435625

Use case

See documentation for zizmor.

Additional context

This auditing should also be done on other bitcoindevkit org repos. In particular bdk-ffi, see: bitcoindevkit/bdk-ffi#638.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status

Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions