Skip to content

ci: add zizmor and pin gradle distribution#8147

Open
bfabio wants to merge 1 commit into
pagopa:masterfrom
bfabio:pin-all-the-things
Open

ci: add zizmor and pin gradle distribution#8147
bfabio wants to merge 1 commit into
pagopa:masterfrom
bfabio:pin-all-the-things

Conversation

@bfabio
Copy link
Copy Markdown
Contributor

@bfabio bfabio commented Jun 1, 2026

Short description

Add a supply chain workflow enforcing GH actions SHA pinning
and more goodies by zizmor.

Pin the gradle distribution by sha256 so a swapped zip from
the CDN fails the build.

Add a supply chain workflow enforcing GH actions SHA pinning
and more goodies by zizmor.

Pin the gradle distribution by sha256 so a swapped zip from
the CDN fails the build.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant