FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

chore(ci): address zizmor findings by torreypayne · Pull Request #36206 · googleapis/google-cloud-ruby · GitHub

chore(ci): address zizmor findings - #36206

Merged
torreypayne merged 2 commits into
mainfrom
chore/zizmor-fixes
Aug 18, 2026
Merged

chore(ci): address zizmor findings#36206
torreypayne merged 2 commits into
mainfrom
chore/zizmor-fixes

Conversation

torreypayne commented Aug 7, 2026
edited
Loading

Copy link
Copy Markdown
Member

📚 PR Stack Navigation

  1. 👉 PR #1: Zizmor Security Audit Fixes (Base - You are here)
  2. PR #2: Doctest Prefactoring (Sample Loader & 11-Gem Mocks)
  3. PR #3: Doctest CI Matrix Switch (Top of Stack)

Addresses ad-hoc package errors and unpinned actions flagged by zizmor.

Context:
This acts as a "prefactoring" step to unblock the upcoming Doctests PR (#36296). Because the doctest PR modifies .github/workflows/ci.yml, it awakened the repository's Zizmor security scanner (which triggers exclusively on modifications strictly within .github/workflows/). That scan surfaced a backlog of accumulated technical debt and unpinned action tags across the workflow files.

By splitting these fixes into this isolated PR, we can cleanly address the baseline workflow debt without polluting the core doctest implementation.

torreypayne force-pushed the chore/zizmor-fixes branch 4 times, most recently from c10e6e3 to 82846d1 Compare August 17, 2026 20:08
torreypayne marked this pull request as ready for review August 17, 2026 23:36
torreypayne requested review from a team and yoshi-approver as code owners August 17, 2026 23:36
torreypayne marked this pull request as draft August 17, 2026 23:55
torreypayne marked this pull request as ready for review August 18, 2026 19:33
torreypayne merged commit 91b4f5b into main Aug 18, 2026
19 checks passed
torreypayne deleted the chore/zizmor-fixes branch August 18, 2026 20:38
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL