mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 01:06:14 +00:00
Set persist-credentials: false on every actions/checkout step, so the job token is not left in .git/config for the rest of the job. No step after checkout pushes or fetches with it. The only authenticated operation, gh release in release.yml, uses GH_TOKEN. Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
78 lines
2.3 KiB
YAML
78 lines
2.3 KiB
YAML
# zizmor configuration — https://docs.zizmor.sh/configuration/
|
|
#
|
|
# Every audit is enforced for every workflow. The per-file ignores below are
|
|
# the findings that already existed when this check was introduced: each one
|
|
# is a pending clean-up, not an accepted risk. New workflows are checked
|
|
# with no exceptions. Remove a file from a list in the same PR that fixes it,
|
|
# and the whole rule entry once its list is empty.
|
|
rules:
|
|
# Avoid installing packages ad hoc inside `run:`.
|
|
adhoc-packages:
|
|
ignore:
|
|
- plugins-deploy-api-doc.yml
|
|
- plugins-deploy-package.yml
|
|
- plugins-deploy-styles-doc.yml
|
|
# Avoid restoring caches in release/publish workflows.
|
|
cache-poisoning:
|
|
ignore:
|
|
- plugins-deploy-api-doc.yml
|
|
- plugins-deploy-styles-doc.yml
|
|
# Review `pull_request_target` usage.
|
|
dangerous-triggers:
|
|
ignore:
|
|
- auto-label.yml
|
|
- commit-checker.yml
|
|
# Declare least-privilege `permissions:` per workflow/job.
|
|
excessive-permissions:
|
|
ignore:
|
|
- auto-label.yml
|
|
- build-adhoc.yml
|
|
- build-bundle.yml
|
|
- build-develop.yml
|
|
- build-docker-admin-console.yml
|
|
- build-docker-devenv.yml
|
|
- build-docker.yml
|
|
- build-staging.yml
|
|
- build-tag.yml
|
|
- build-tmp-tokens.yml
|
|
- commit-checker.yml
|
|
- plugins-deploy-packages.yml
|
|
- tests-backend.yml
|
|
- tests-common.yml
|
|
- tests-e2e.yml
|
|
- tests-exporter.yml
|
|
- tests-frontend.yml
|
|
- tests-library.yml
|
|
- tests-mcp.yml
|
|
- tests-plugins.yml
|
|
- tests-wasm.yml
|
|
# Scope GitHub App tokens.
|
|
github-app:
|
|
ignore:
|
|
- auto-label.yml
|
|
# Pass only the secrets each reusable workflow needs.
|
|
secrets-inherit:
|
|
ignore:
|
|
- build-adhoc.yml
|
|
- build-develop.yml
|
|
- build-staging.yml
|
|
- build-tag.yml
|
|
- build-tmp-tokens.yml
|
|
- plugins-deploy-packages.yml
|
|
# Style nudge towards the `$/...` syntax; not worth enforcing.
|
|
self-repository:
|
|
disable: true
|
|
# Pin container images to a digest.
|
|
unpinned-images:
|
|
ignore:
|
|
- plugins-deploy-package.yml
|
|
- tests-backend.yml
|
|
- tests-common.yml
|
|
- tests-e2e.yml
|
|
- tests-exporter.yml
|
|
- tests-frontend.yml
|
|
- tests-library.yml
|
|
- tests-mcp.yml
|
|
- tests-plugins.yml
|
|
- tests-wasm.yml
|