Skip to content

Add pinact and zizmor workflow checks #1

Add pinact and zizmor workflow checks

Add pinact and zizmor workflow checks #1

Triggered via pull request April 28, 2026 13:29
Status Failure
Total duration 17s
Artifacts

zizmor.yaml

on: pull_request
Run zizmor
12s
Run zizmor
Fit to window
Zoom out
Zoom in

Annotations

5 errors
Run zizmor
Process completed with exit code 14.
unpinned-uses: .github/workflows/triage.yaml#L18
triage.yaml:18: unpinned action reference: action is not pinned to a hash (required by blanket policy)
cache-poisoning: .github/workflows/release.yaml#L15
release.yaml:15: runtime artifacts potentially vulnerable to a cache poisoning attack: enables caching by default
bot-conditions: .github/workflows/dependabot-changie.yaml#L15
dependabot-changie.yaml:15: spoofable bot actor check: actor context may be spoofable
unpinned-uses: .github/workflows/dependabot-changie.yaml#L32
dependabot-changie.yaml:32: unpinned action reference: action is not pinned to a hash (required by blanket policy)