Post #1734886
2026-04-27 19:23 UTC
RE: https://mastodon.social/@andrewnez/116478133377243019
Workflow security continues to be a common cause of compromises of open source projects.
If you're using GitHub Actions and don't want this to happen to your project: use Zizmor and treat the findings seriously, especially insecure triggers and user-controllable template injections.
https://docs.zizmor.sh
#github #actions #security #oss #opensource #python
Replies (1)
-
@westonsteimel@hachyderm.io 2026-04-27 19:29
@sethmlarson@mastodon.social And if you need time to work through all of the findings, consider at least forcing approvals for all external contributors (not just first time) to prevent them from executing