Skip to content

ci: add zizmor workflow#2176

Open
Sheraff wants to merge 3 commits into
TanStack:mainfrom
Sheraff:ci/add-zizmor
Open

ci: add zizmor workflow#2176
Sheraff wants to merge 3 commits into
TanStack:mainfrom
Sheraff:ci/add-zizmor

Conversation

@Sheraff
Copy link
Copy Markdown

@Sheraff Sheraff commented May 12, 2026

Summary

  • Add a pinned zizmor workflow for GitHub Actions security analysis.
  • Fix existing zizmor findings by pinning actions, disabling checkout credential persistence, and scoping PR write permissions to the job that needs them.

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new Bot commented May 12, 2026

More templates

@tanstack/angular-form

npm i https://pkg.pr.new/@tanstack/angular-form@2176

@tanstack/form-core

npm i https://pkg.pr.new/@tanstack/form-core@2176

@tanstack/form-devtools

npm i https://pkg.pr.new/@tanstack/form-devtools@2176

@tanstack/lit-form

npm i https://pkg.pr.new/@tanstack/lit-form@2176

@tanstack/preact-form

npm i https://pkg.pr.new/@tanstack/preact-form@2176

@tanstack/react-form

npm i https://pkg.pr.new/@tanstack/react-form@2176

@tanstack/react-form-devtools

npm i https://pkg.pr.new/@tanstack/react-form-devtools@2176

@tanstack/react-form-nextjs

npm i https://pkg.pr.new/@tanstack/react-form-nextjs@2176

@tanstack/react-form-remix

npm i https://pkg.pr.new/@tanstack/react-form-remix@2176

@tanstack/react-form-start

npm i https://pkg.pr.new/@tanstack/react-form-start@2176

@tanstack/solid-form

npm i https://pkg.pr.new/@tanstack/solid-form@2176

@tanstack/solid-form-devtools

npm i https://pkg.pr.new/@tanstack/solid-form-devtools@2176

@tanstack/svelte-form

npm i https://pkg.pr.new/@tanstack/svelte-form@2176

@tanstack/vue-form

npm i https://pkg.pr.new/@tanstack/vue-form@2176

commit: c9614c3

Comment thread .github/workflows/release.yml Outdated
Comment thread .github/workflows/pr.yml Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants