Skip to content

Add security workflows #7

Add security workflows

Add security workflows #7

Triggered via pull request November 27, 2025 16:37
@maxammannmaxammann
synchronize #6
security
Status Failure
Total duration 11s
Artifacts

security-testing-pr.yml

on: pull_request
zizmor latest via PyPI
7s
zizmor latest via PyPI
Fit to window
Zoom out
Zoom in

Annotations

2 errors and 4 warnings
zizmor latest via PyPI
Process completed with exit code 14.
unpinned-images: .github/workflows/security-pr.yml#L21
security-pr.yml:21: unpinned image references: container image is unpinned
artipacked: .github/workflows/security-pr.yml#L24
security-pr.yml:24: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
artipacked: .github/workflows/security-default-branch.yml#L25
security-default-branch.yml:25: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
overprovisioned-secrets: .github/workflows/gha-secret-extract.yaml#L14
gha-secret-extract.yaml:14: excessively provisioned secrets: injects the entire secrets context into the runner
zizmor latest via PyPI
No file matched to [/home/runner/work/gha-workflows/gha-workflows/**/*requirements*.txt,/home/runner/work/gha-workflows/gha-workflows/**/*requirements*.in,/home/runner/work/gha-workflows/gha-workflows/**/*constraints*.txt,/home/runner/work/gha-workflows/gha-workflows/**/*constraints*.in,/home/runner/work/gha-workflows/gha-workflows/**/pyproject.toml,/home/runner/work/gha-workflows/gha-workflows/**/uv.lock,/home/runner/work/gha-workflows/gha-workflows/**/*.py.lock]. The cache will never get invalidated. Make sure you have checked out the target repository and configured the cache-dependency-glob input correctly.