Audit GHA workflows with zizmor (#1136)
* Don't persist credentials in pypi.yml
Ref: <https://woodruffw.github.io/zizmor/audits/#artipacked>
* Don't persist credentials
This is an insecure default on GitHub that increases the chances of credential leakage.
<https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/>
* Add zizmor exception for RTD pull_request_target trigger
* Create zizmor workflow
正在显示
.github/workflows/zizmor.yml
0 → 100644
请
注册
或者
登录
后发表评论