Pins every action to the latest release SHA within its current major, so no untested major bump rides along: checkout v4.4.0, setup-go v5.6.0, upload-artifact v4.6.2, download-artifact v4.3.0, action-gh-release v2.6.2. Adds a `workflows` CI job running actionlint and zizmor. actionlint comes from `go install` (module proxy checksums cover integrity); zizmor has no published checksums, so its release tarball is pinned by version and verified against a recorded sha256. The gate uses --min-severity=low, which fails on low and above while tolerating the one informational superfluous-actions advisory. zizmor only collects from .github/workflows: pointing it at .gitea/workflows yields "no inputs collected", and when both directories are passed it audits only .github and still exits 0. The gate therefore passes explicit *.yml paths, which is the only form that actually audits the Gitea workflows. Auditing them for the first time surfaced seven findings, now fixed: credential persistence on checkout (persist-credentials: false), setup-go caching on the release path (cache: false), and missing top-level permissions (contents: read, with contents: write narrowed to the GitHub release job that needs it).