Skip to content

ci: Address zizmor warnings and bump actions - #65

Merged
Techassi merged 5 commits into
stackabletech:mainfrom
Saul-STFC:CI-Hardening
Sep 1, 2026
Merged

ci: Address zizmor warnings and bump actions#65
Techassi merged 5 commits into
stackabletech:mainfrom
Saul-STFC:CI-Hardening

Conversation

@Saul-STFC

@Saul-STFC Saul-STFC commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

This PR adds CI Hardening to the repo

This addresses all warnings from Zizmor and also bumps dependency versions.

@Techassi Techassi moved this to Development: In Review in Stackable Engineering Aug 31, 2026
@Techassi Techassi changed the title CI: Address zizmor warnings and bump deps ci: Address zizmor warnings and bump actions Aug 31, 2026

@Techassi Techassi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Generally looks good, but we should switch the file extensions.

Comment thread .github/workflows/maven.yaml
Comment thread .github/workflows/reviewdog.yaml
@Techassi

Techassi commented Sep 1, 2026

Copy link
Copy Markdown
Member

The CI failure is expected as this PR is raised from a fork. Ideally, we should gate this step/job if it comes from a fork.

See advanced-security/maven-dependency-submission-action#55

@Techassi Techassi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved.

CC'ing @dervoeti for a second pair of eyes.

@Techassi
Techassi added this pull request to the merge queue Sep 1, 2026
@Techassi Techassi moved this from Development: In Review to Development: Done in Stackable Engineering Sep 1, 2026
Merged via the queue into stackabletech:main with commit 1247b35 Sep 1, 2026
8 checks passed
@lfrancke lfrancke moved this from Development: Done to Done in Stackable Engineering Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

4 participants