chore(ci): add secure runner across workflows - #914
Merged
Merged
Conversation
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
grandizzy
marked this pull request as ready for review
September 18, 2026 17:18
grandizzy
requested review from
0xrusowsky,
DaniPopes,
grandizzy,
mattsse and
onbjerg
as code owners
September 18, 2026 17:18
grandizzy
enabled auto-merge (squash)
September 18, 2026 17:18
grandizzy
approved these changes
Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add the pinned secure-runner action before checkout in build, test, formatting, typo, CodeQL, and release-branch sync jobs, with job-scoped OIDC permissions. The matrix generator and final result aggregation do not install dependencies and are unchanged.
Foundry/solc binaries and Git dependencies are not covered by registry package checks.
Validation: actionlint passed (with existing Depot labels configured where needed), git diff --check passed, and a YAML coverage audit confirmed the first-step ordering, OIDC permissions, preserved triggers/matrices, and intended exclusions. Offline zizmor introduced no new findings relative to the base branch; existing findings remain. GitHub CI and workflows triggered only by schedules/releases/Dependabot still require runtime validation.
The action's documented fork-PR fallback skips package-policy enforcement when GitHub withholds OIDC. Existing caches are retained and are not rescanned.
Prepared with AI assistance.
Prompted by: @grandizzy