Skip to content

fix: resolve zizmor GitHub Actions security findings#516

Open
dgilmanuni wants to merge 1 commit intomainfrom
fix/zizmor-security-findings
Open

fix: resolve zizmor GitHub Actions security findings#516
dgilmanuni wants to merge 1 commit intomainfrom
fix/zizmor-security-findings

Conversation

@dgilmanuni
Copy link
Contributor

Summary

  • Ran zizmor static analysis on GitHub Actions workflows
  • Fixed credential persistence issues (persist-credentials: false)
  • Added minimal permissions blocks where missing
  • Fixed template injection vulnerabilities where auto-fixable

Generated by zizmor v1.22.0

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@graphite-app graphite-app bot requested a review from a team February 12, 2026 21:09
@graphite-app graphite-app bot requested a review from a team February 12, 2026 21:09
@graphite-app
Copy link

graphite-app bot commented Feb 12, 2026

Graphite Automations

"Request reviewers once CI passes on sdks monorepo" took an action on this PR • (02/12/26)

3 reviewers were added and 1 assignee was added to this PR based on Siyu Jiang (See-You John)'s automation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant