Skip to content

Add zizmor to git hooks and CI - #9135

Draft
ulgens wants to merge 6 commits into
processing:mainfrom
ulgens:zizmor
Draft

ulgens wants to merge 6 commits into
processing:mainfrom
ulgens:zizmor

Conversation

@ulgens

@ulgens ulgens commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Relates to:

Depends on:

Changes:
Add zizmor to git hooks and CI

PR Checklist

  • npm run lint passes
  • [Inline reference] is included / updated
  • [Unit tests] are included / updated

@ulgens
ulgens marked this pull request as ready for review September 12, 2026 23:08

@Vaivaswat2244 Vaivaswat2244 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @ulgens! Thanks for the pr. Hashes check out and the new workflow is clean under zizmor.

The Git Hooks job hasn't run here yet. Could you run the hooks on this branch once? I ran prek run --all-files and got exit 14 with 58 findings locally, mostly in the release workflows, and want to confirm that matches before we decide how to sequence this.

@ulgens
ulgens marked this pull request as draft September 21, 2026 14:05
@ulgens

ulgens commented Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

@Vaivaswat2244 You are right and I'm not sure how I forgot that.

I'll incrementally update the PR to handle them.

https://docs.zizmor.sh/audits/#secrets-outside-env

I'm not exactly sure about benefits of this rule and fixing the violations require changes in repo settings. Disabling for now, can be revisited later.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants