Thanks to visit codestin.com
Credit goes to github.com

Skip to content

GitHub Actions - security updates#7138

Merged
bentsherman merged 4 commits into
masterfrom
gha-updates
May 13, 2026
Merged

GitHub Actions - security updates#7138
bentsherman merged 4 commits into
masterfrom
gha-updates

Conversation

@ewels

@ewels ewels commented May 13, 2026

Copy link
Copy Markdown
Member

Combination of using https://zizmor.sh/ and actions-up and Claude to try to beef up the security a bit in the GitHub actions automations.

ewels added 3 commits May 13, 2026 11:40
… config

- Add explicit permissions blocks (workflow + job level, contents: read
  where possible) to build, cffconvert, docs, stale
- stale job gets issues: write + pull-requests: write (only what
  actions/stale actually needs)
- Move github.event.pusher.name/email out of the git config run script
  and into env vars to prevent shell injection via a malicious pusher

Signed-off-by: Phil Ewels <[email protected]>
@netlify

netlify Bot commented May 13, 2026

Copy link
Copy Markdown

Deploy Preview for nextflow-docs-staging canceled.

Name Link
🔨 Latest commit 6f98348
🔍 Latest deploy log https://app.netlify.com/projects/nextflow-docs-staging/deploys/6a0452ab058e5c0008c6e8fc

@bentsherman bentsherman merged commit 5e2ef57 into master May 13, 2026
24 checks passed
@bentsherman bentsherman deleted the gha-updates branch May 13, 2026 13:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants