#githubactions

3 posts· Last used Jul 23

CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈 Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way: https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/ #php #phpc #composerphp #github #githubactions #supplychainsecurity
9
0
9
1
You've seen all posts