Skip to content

Enable zizmor static checker #1534

@jvanz

Description

@jvanz

Due some recent events regarding to security issue around GHA misconfiguration, we would live to be pro active and improve our security as well. For that, the Kubewarden team want to enable Zizmor static checker to spot issue in out Github actions usage.

Acceptance criteria

  • Add a CI step to run Zizmor
  • Add a Makefile target to run Zizmor locally
  • Run Zizmor and check if there is some issue. If so, fix it.

Metadata

Metadata

Assignees

Projects

Status

Pending review

Relationships

None yet

Development

No branches or pull requests

Issue actions