Files
Mike Dalessio e62fcc3b58 ci: harden GitHub Actions workflows (#1284)
* Add GitHub Actions audit job (actionlint + zizmor)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Configure dependabot for github-actions, npm, and bundler with batching and cooldowns

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Add local GitHub Actions linting (actionlint + zizmor) to bin/setup and bin/ci

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Pin all GitHub Actions to SHA hashes

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Fix zizmor findings: add permissions and persist-credentials: false

Set workflow-level permissions: {} and add per-job contents: read.
Add persist-credentials: false to all checkout steps.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-20 19:34:00 -04:00
..
2016-04-30 15:44:56 -04:00
2021-03-11 10:26:49 -05:00