I learned recently about zizmor - a tool that audits your GH Actions..
TIL there is a GH-Action for zizmor but it updates the GH Security Section with findings... I didn't know that was possible.
I learned recently about zizmor - a tool that audits your GH Actions..
TIL there is a GH-Action for zizmor but it updates the GH Security Section with findings... I didn't know that was possible.
↗ https://github.com/zizmorcore/zizmor-action#usage-with-github-advanced-security-recommended