ci: pin containers to digest, enable more zizmor rules (#38779)

Enable more strict "pedantic" zizmor rules and fix issues. Service
containers are pinned to hash and renovate will update them. Enabled
rules:

- https://docs.zizmor.sh/audits/#excessive-permissions
- https://docs.zizmor.sh/audits/#unpinned-images
- https://docs.zizmor.sh/audits/#template-injection

---------

Signed-off-by: silverwind <me@silverwind.io>
This commit is contained in:
silverwind
2026-08-06 07:16:07 +02:00
committed by GitHub
parent d94f714efa
commit d8c3a1afda
14 changed files with 47 additions and 20 deletions
+3 -2
View File
@@ -9,8 +9,7 @@ on:
workflow_dispatch:
workflow_call:
permissions:
actions: write # to delete caches
permissions: {}
concurrency:
group: cache-prune
@@ -19,6 +18,8 @@ jobs:
prune:
runs-on: ubuntu-latest
if: github.repository == 'go-gitea/gitea'
permissions:
actions: write # to delete caches
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}