Elektrine lite

← Feed

@sethmlarson@mastodon.social

Post #1734886

2026-04-27 19:23 UTC

RE: https://mastodon.social/@andrewnez/116478133377243019 Workflow security continues to be a common cause of compromises of open source projects. If you're using GitHub Actions and don't want this to happen to your project: use Zizmor and treat the findings seriously, especially insecure triggers and user-controllable template injections. https://docs.zizmor.sh #github #actions #security #oss #opensource #python

Replies (1)

  • @westonsteimel@hachyderm.io 2026-04-27 19:29

    @sethmlarson@mastodon.social And if you need time to work through all of the findings, consider at least forcing approvals for all external contributors (not just first time) to prevent them from executing

    Open ##2420227