Skip to content
Discussion options

You must be logged in to vote

I can't find where I wrote it before, but the TL;DR is that zizmor is focused on security checks only, not general correctness/well-formedness checks (although some of those happen by "accident" as part of us parsing inputs for analysis).

So, anything that actionlint does that has some security salience is potentially in scope. But things that just flag footguns e.g. when pushing invalid syntax aren't.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by woodruffw
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants