Skip to content

ci: Fix zizmor warnings and bump actions - #447

Open
Saul-STFC wants to merge 1 commit into
stackabletech:mainfrom
Saul-STFC:CI-Hardening
Open

ci: Fix zizmor warnings and bump actions#447
Saul-STFC wants to merge 1 commit into
stackabletech:mainfrom
Saul-STFC:CI-Hardening

Conversation

@Saul-STFC

Copy link
Copy Markdown

This PR explicitly defines permissions fixing zizmor warnings and also bumps deps

@Techassi Techassi moved this to Development: In Review in Stackable Engineering Aug 31, 2026
@Techassi Techassi changed the title CI: Fix zizmor warnings and bump deps ci: Fix zizmor warnings and bump actions Aug 31, 2026
notify:
name: Failure Notification
needs: [build, publish_manifests]
permissions: {}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm curious why we need to explicitly set an empty set of permissions here, if the workflow-wide default is empty as well ({}).

Comment on lines +98 to +99
# Pinned to the latest v1.x patch, not v4 (latest): v2+ has breaking changes
- uses: slackapi/slack-github-action@fcfb566f8b0aab22203f066d80ca1d7e4b5d05b3 # v1.27.1

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should switch to our own stackabletech/send-slack-notification action in a follow-up PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Development: In Review

Development

Successfully merging this pull request may close these issues.

2 participants