|
I would love to know which audit rules and lint checks covered by actionlint, that |
Answered by
woodruffw
Aug 31, 2026
Replies: 1 comment
|
I can't find where I wrote it before, but the TL;DR is that zizmor is focused on security checks only, not general correctness/well-formedness checks (although some of those happen by "accident" as part of us parsing inputs for analysis). So, anything that actionlint does that has some security salience is potentially in scope. But things that just flag footguns e.g. when pushing invalid syntax aren't. |
0 replies
Answer selected by
woodruffw
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
I can't find where I wrote it before, but the TL;DR is that zizmor is focused on security checks only, not general correctness/well-formedness checks (although some of those happen by "accident" as part of us parsing inputs for analysis).
So, anything that actionlint does that has some security salience is potentially in scope. But things that just flag footguns e.g. when pushing invalid syntax aren't.