Commit 2d3f255
fix: harden GitHub Actions workflows (zizmor) (#8)
Disable secrets-outside-env rule via .github/zizmor.yml config. This
rule flags secrets used outside dedicated GitHub environments, which is
an organizational policy choice rather than a direct vulnerability.
All 4 medium-severity findings (secrets-outside-env in aliases.yml and
release.yml) are resolved.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 937f824 commit 2d3f255
1 file changed
Lines changed: 3 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
0 commit comments