summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJacob Walls <jacobtylerwalls@gmail.com>2026-04-10 08:21:46 -0400
committernessita <124304+nessita@users.noreply.github.com>2026-04-13 13:04:48 -0300
commitf0b75f46fd0ee98c10887b3c5dc4593d2bccf821 (patch)
treee051477a2d4d1c1ba6247fa619e5bea18c00efa5
parent746f5fd23e50589ef3ad27b1dad46b569f600fa0 (diff)
Removed unused code checkout step from labels.yml GitHub Action.
-rw-r--r--.github/workflows/labels.yml4
-rw-r--r--zizmor.yml2
2 files changed, 2 insertions, 4 deletions
diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml
index 2f319627c7..3042f4d228 100644
--- a/.github/workflows/labels.yml
+++ b/.github/workflows/labels.yml
@@ -21,10 +21,6 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
- - uses: actions/checkout@v6
- with:
- persist-credentials: false
-
- name: "Check title and manage labels"
uses: actions/github-script@v8
with:
diff --git a/zizmor.yml b/zizmor.yml
index 23630337b4..19493ba151 100644
--- a/zizmor.yml
+++ b/zizmor.yml
@@ -1,5 +1,7 @@
rules:
dangerous-triggers:
+ # Before ignoring a file, assume all inputs are malicious, assign explicit
+ # minimal permissions, and do not use actions/checkout.
ignore:
- coverage_comment.yml
- labels.yml