Skip to content

Use zizmor and various CI updates - #328

Open
jarrodmillman wants to merge 1 commit into
scientific-python:mainfrom
jarrodmillman:updates
Open

jarrodmillman wants to merge 1 commit into
scientific-python:mainfrom
jarrodmillman:updates

Conversation

@jarrodmillman

Copy link
Copy Markdown
Member

No description provided.

@jarrodmillman jarrodmillman added the type: Maintenance Refactoring and maintenance of internals label Oct 7, 2026

@stefanv stefanv left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Why do we need the ignore dangerous triggers?

@jarrodmillman

Copy link
Copy Markdown
Member Author

LGTM. Why do we need the ignore dangerous triggers?

Otherwise we get this error

error[dangerous-triggers]: use of fundamentally insecure workflow trigger
 --> ./.github/workflows/milestone-merged-prs.yaml:3:1
  |
3 | / on:
4 | |   pull_request_target:
5 | |     types:
6 | |       - closed
7 | |     branches:
8 | |       - "main"
  | |______________^ pull_request_target is almost always used insecurely
  |
  = note: audit confidence → Medium

See scikit-image/scikit-image@25cc275

@jarrodmillman

Copy link
Copy Markdown
Member Author

Still getting

info[template-injection]: code injection via template expansion
  --> .github/workflows/test.yml:43:34
   |
42 |         run: |
   |         --- this run block
43 |           pipx run --python '${{ steps.setup-python.outputs.python-path }}' nox --forcecolor -s test
   |                                  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ may expand into attacker-controllable code
   |
   = note: audit confidence → Low

@stefanv

stefanv commented Oct 7, 2026

Copy link
Copy Markdown
Member

Why are we using pull_request_target? I think that's only for when we need to share secrets.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: Maintenance Refactoring and maintenance of internals

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants