Skip to content

Partially Harden CI#5563

Merged
hyperupcall merged 4 commits intoSchemaStore:masterfrom
hyperupcall:hyperupcall-hardenci
Apr 12, 2026
Merged

Partially Harden CI#5563
hyperupcall merged 4 commits intoSchemaStore:masterfrom
hyperupcall:hyperupcall-hardenci

Conversation

@hyperupcall
Copy link
Copy Markdown
Member

@hyperupcall hyperupcall commented Apr 12, 2026

In the past year we've seen an acceleration of the frequency of malware targeting the JavaScript ecosystem and GitHub. Let's be proactive about it.

I'm using pinact and Zizmor to manage the pinning of versions with their hash.

There is definitely more to do, this is just a first easy step that allows our CI to be "hardened" and continue working without troubleshooting issues related to lack of permissions etc.

Remove rarely used and no-longer used labels so it's easier searching for
labels that are actually used.
@github-actions github-actions bot added the CI ".github/**/*" folder is updated (auto-generated by labeler action) label Apr 12, 2026
@github-actions
Copy link
Copy Markdown
Contributor

Thanks for the PR!

This section of the codebase is owned by @madskristensen and @hyperupcall - if they write a comment saying "LGTM" then it will be merged.

@hyperupcall hyperupcall changed the title Harden CI Partially \Harden CI Apr 12, 2026
@hyperupcall hyperupcall changed the title Partially \Harden CI Partially Harden CI Apr 12, 2026
@hyperupcall hyperupcall merged commit 1bb1478 into SchemaStore:master Apr 12, 2026
4 checks passed
@hyperupcall hyperupcall deleted the hyperupcall-hardenci branch April 12, 2026 08:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI ".github/**/*" folder is updated (auto-generated by labeler action)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant