Skip to content

ci: add zizmor workflow#10700

Merged
lachlancollins merged 3 commits into
TanStack:mainfrom
Sheraff:ci/add-zizmor
May 13, 2026
Merged

ci: add zizmor workflow#10700
lachlancollins merged 3 commits into
TanStack:mainfrom
Sheraff:ci/add-zizmor

Conversation

@Sheraff
Copy link
Copy Markdown
Contributor

@Sheraff Sheraff commented May 12, 2026

Summary

  • Add a pinned zizmor workflow for GitHub Actions security analysis.
  • Harden existing workflows by pinning actions, disabling persisted checkout credentials, and narrowing write permissions to jobs.
  • Move shell-interpolated GitHub expressions into environment variables where needed.

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new Bot commented May 12, 2026

More templates

@tanstack/angular-query-experimental

npm i https://pkg.pr.new/@tanstack/angular-query-experimental@10700

@tanstack/eslint-plugin-query

npm i https://pkg.pr.new/@tanstack/eslint-plugin-query@10700

@tanstack/lit-query

npm i https://pkg.pr.new/@tanstack/lit-query@10700

@tanstack/preact-query

npm i https://pkg.pr.new/@tanstack/preact-query@10700

@tanstack/preact-query-devtools

npm i https://pkg.pr.new/@tanstack/preact-query-devtools@10700

@tanstack/preact-query-persist-client

npm i https://pkg.pr.new/@tanstack/preact-query-persist-client@10700

@tanstack/query-async-storage-persister

npm i https://pkg.pr.new/@tanstack/query-async-storage-persister@10700

@tanstack/query-broadcast-client-experimental

npm i https://pkg.pr.new/@tanstack/query-broadcast-client-experimental@10700

@tanstack/query-core

npm i https://pkg.pr.new/@tanstack/query-core@10700

@tanstack/query-devtools

npm i https://pkg.pr.new/@tanstack/query-devtools@10700

@tanstack/query-persist-client-core

npm i https://pkg.pr.new/@tanstack/query-persist-client-core@10700

@tanstack/query-sync-storage-persister

npm i https://pkg.pr.new/@tanstack/query-sync-storage-persister@10700

@tanstack/react-query

npm i https://pkg.pr.new/@tanstack/react-query@10700

@tanstack/react-query-devtools

npm i https://pkg.pr.new/@tanstack/react-query-devtools@10700

@tanstack/react-query-next-experimental

npm i https://pkg.pr.new/@tanstack/react-query-next-experimental@10700

@tanstack/react-query-persist-client

npm i https://pkg.pr.new/@tanstack/react-query-persist-client@10700

@tanstack/solid-query

npm i https://pkg.pr.new/@tanstack/solid-query@10700

@tanstack/solid-query-devtools

npm i https://pkg.pr.new/@tanstack/solid-query-devtools@10700

@tanstack/solid-query-persist-client

npm i https://pkg.pr.new/@tanstack/solid-query-persist-client@10700

@tanstack/svelte-query

npm i https://pkg.pr.new/@tanstack/svelte-query@10700

@tanstack/svelte-query-devtools

npm i https://pkg.pr.new/@tanstack/svelte-query-devtools@10700

@tanstack/svelte-query-persist-client

npm i https://pkg.pr.new/@tanstack/svelte-query-persist-client@10700

@tanstack/vue-query

npm i https://pkg.pr.new/@tanstack/vue-query@10700

@tanstack/vue-query-devtools

npm i https://pkg.pr.new/@tanstack/vue-query-devtools@10700

commit: c484f23

Comment thread .github/workflows/release.yml Outdated
@lachlancollins lachlancollins merged commit e220149 into TanStack:main May 13, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants