Skip to content

[pull] master from CycloneDX:master#48

Merged
pull[bot] merged 1 commit into
turkdevops:masterfrom
CycloneDX:master
May 8, 2026
Merged

[pull] master from CycloneDX:master#48
pull[bot] merged 1 commit into
turkdevops:masterfrom
CycloneDX:master

Conversation

@pull
Copy link
Copy Markdown

@pull pull Bot commented May 8, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

…ial handling (#925)

This PR adds a [zizmor](https://github.com/woodruffw/zizmor)
security-scanning workflow and hardens the existing GitHub Actions
workflows against credential-leakage risks.

Changes include:
- New `.github/workflows/zizmor.yml` that runs the zizmor
static-analysis tool on every push and pull-request, and on
`dependabot.yml` changes.
- All `actions/checkout` steps now use `persist-credentials: false` to
avoid leaving GitHub tokens in the workspace.
- All third-party Actions are pinned to their full commit SHA (with a
human-readable version comment) so supply-chain substitutions are
detectable.
- A cooldown configuration block added to `dependabot.yml` to reduce
noise from automated updates.

fixes #924

---------

Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: jkowalleck <2765863+jkowalleck@users.noreply.github.com>
Co-authored-by: Jan Kowalleck <jan.kowalleck@owasp.org>
Co-authored-by: Jan Kowalleck <jan.kowalleck@gmail.com>
@pull pull Bot locked and limited conversation to collaborators May 8, 2026
@pull pull Bot added the ⤵️ pull label May 8, 2026
@pull pull Bot merged commit 3749afd into turkdevops:master May 8, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant