github: scope/narrow permissions, prevent template injection via GHA, enable zizmor workflow #1
zizmor.yml
on: pull_request
Run zizmor on all workflows
35s
Annotations
1 warning
Run zizmor on all workflows
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|