ci: address zizmor findings #68
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This addresses a bunch of findings from
zizmor
, both low-impact (mostly credential persistence/permission minimization) as well as some potential template injections (non-exploitable in this case, but good to remove!)I've also gone ahead and bumped the versions on a couple of actions, where they were outdated.
NB: This changeset doesn't include a new workflow for
zizmor
, but if folks are interested this one should be drag-n-drop 🙂Afterwards: