Skip to content

[CI] should we use zizmor in CI to scan jobs for problems? #49732

@thisisnic

Description

@thisisnic

Describe the enhancement

We could use zizmor to scan CI for problems.

Some of the findings on an initial scan were false positives or no-ops when looked at in the context of other mitigations, so we'd need to think about this if we go ahead with it to make sure we're not triggering a ton of unnecessary notifications.

We can disable certain rules if they're annoying though: https://docs.zizmor.sh/configuration/#rulesiddisable

Component(s)

Continuous Integration

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions