Files
shush/.gitea/workflows
mroberts 250b3e98ca
CI / build (push) Successful in 49s
CI / workflows (push) Successful in 16s
Release / release (push) Failing after 19s
ci: pin actions to SHAs and gate workflows on actionlint + zizmor
Pins every action to the latest release SHA within its current major, so
no untested major bump rides along: checkout v4.4.0, setup-go v5.6.0,
upload-artifact v4.6.2, download-artifact v4.3.0, action-gh-release v2.6.2.

Adds a `workflows` CI job running actionlint and zizmor. actionlint comes
from `go install` (module proxy checksums cover integrity); zizmor has no
published checksums, so its release tarball is pinned by version and
verified against a recorded sha256. The gate uses --min-severity=low, which
fails on low and above while tolerating the one informational
superfluous-actions advisory.

zizmor only collects from .github/workflows: pointing it at .gitea/workflows
yields "no inputs collected", and when both directories are passed it audits
only .github and still exits 0. The gate therefore passes explicit *.yml
paths, which is the only form that actually audits the Gitea workflows.

Auditing them for the first time surfaced seven findings, now fixed:
credential persistence on checkout (persist-credentials: false), setup-go
caching on the release path (cache: false), and missing top-level
permissions (contents: read, with contents: write narrowed to the GitHub
release job that needs it).
2026-07-21 15:16:55 -05:00
..