Skip to content

Bump the github-actions group across 1 directory with 2 updates #73

Bump the github-actions group across 1 directory with 2 updates

Bump the github-actions group across 1 directory with 2 updates #73

Triggered via pull request August 1, 2026 03:22
Status Failure
Total duration 1m 4s
Artifacts 2

github_actions_scan.yml Required

on: pull_request_target
check-changes
5s
check-changes
zizmor-config
9s
zizmor-config
zizmor-scan
11s
zizmor-scan
zizmor-output
9s
zizmor-output
zizmor-upload
4s
zizmor-upload
Fit to window
Zoom out
Zoom in

Annotations

20 errors, 6 warnings, and 1 notice
zizmor/unpinned-uses: .github/workflows/ci.yml#L118
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor/unpinned-uses: .github/workflows/ci.yml#L116
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor/unpinned-uses: .github/workflows/ci.yml#L94
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor/unpinned-uses: .github/workflows/ci.yml#L92
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor/unpinned-uses: .github/workflows/ci.yml#L88
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor/unpinned-uses: .github/workflows/ci.yml#L63
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor/unpinned-uses: .github/workflows/ci.yml#L57
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor/unpinned-uses: .github/workflows/ci.yml#L54
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor/unpinned-uses: .github/workflows/ci.yml#L50
unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor-output
Found 21 findings for mandatory checks that must always succeed.
template-injection: .github/workflows/release.yml#L115
release.yml:115: code injection via template expansion: may expand into attacker-controllable code
unpinned-uses: .github/workflows/ci.yml#L118
ci.yml:118: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/ci.yml#L116
ci.yml:116: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/ci.yml#L94
ci.yml:94: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/ci.yml#L92
ci.yml:92: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/ci.yml#L88
ci.yml:88: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/ci.yml#L63
ci.yml:63: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/ci.yml#L57
ci.yml:57: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/ci.yml#L54
ci.yml:54: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/ci.yml#L50
ci.yml:50: unpinned action reference: action is not pinned to a hash (required by blanket policy)
zizmor-config
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
zizmor-upload
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
excessive-permissions: .github/workflows/ci.yml#L109
ci.yml:109: overly broad permissions: default permissions used due to no permissions: block
excessive-permissions: .github/workflows/ci.yml#L75
ci.yml:75: overly broad permissions: default permissions used due to no permissions: block
excessive-permissions: .github/workflows/ci.yml#L26
ci.yml:26: overly broad permissions: default permissions used due to no permissions: block
excessive-permissions: .github/workflows/ci.yml#L15
ci.yml:15: overly broad permissions: default permissions used due to no permissions: block
superfluous-actions: .github/workflows/release.yml#L77
release.yml:77: action functionality is already included by the runner: use `gh release` in a script step

Artifacts

Produced during runtime
Name Size Digest
zizmor Expired
8.16 KB
sha256:97fa4b6f8f6053698b0c0ec519654bfd16ce8a014b0caf5a090cdcab7dc35247
zizmor-config Expired
295 Bytes
sha256:edc2623cef014466d43d358c3f377f408d8b6a96b2e41e32c59e3b4a09b40211