Skip to content

ci: fix broken workflows, tighten permissions, add community health files - #1374

Draft
Hunter275 wants to merge 1 commit into
meshtastic:mainfrom
Hunter275:claude-github-fixes
Draft

ci: fix broken workflows, tighten permissions, add community health files#1374
Hunter275 wants to merge 1 commit into
meshtastic:mainfrom
Hunter275:claude-github-fixes

ci: fix broken workflows, tighten permissions, add community health f…

7cb9096
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / zizmor failed Aug 1, 2026 in 10s

16 new alerts including 11 errors

New alerts in code changed by this pull request

  • 11 errors
  • 5 notes

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 54 in .github/workflows/e2e.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 29 in .github/workflows/nightly.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 124 in .github/workflows/nightly.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 127 in .github/workflows/nightly.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 136 in .github/workflows/nightly.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 83 in .github/workflows/release-protobufs.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 147 in .github/workflows/release-protobufs.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 33 in .github/workflows/workflow-lint.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 48 in .github/workflows/workflow-lint.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 51 in .github/workflows/workflow-lint.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check failure on line 64 in .github/workflows/workflow-lint.yml

See this annotation in the file changed.

Code scanning / zizmor

unpinned action reference: action is not pinned to a hash (required by blanket policy) Error

unpinned action reference: action is not pinned to a hash (required by blanket policy)

Check notice on line 29 in .github/workflows/nightly.yml

See this annotation in the file changed.

Code scanning / zizmor

credential persistence through GitHub Actions artifacts: does not set persist-credentials: false Note

credential persistence through GitHub Actions artifacts: does not set persist-credentials: false

Check notice on line 156 in .github/workflows/nightly.yml

See this annotation in the file changed.

Code scanning / zizmor

code injection via template expansion: may expand into attacker-controllable code Note

code injection via template expansion: may expand into attacker-controllable code

Check notice on line 156 in .github/workflows/nightly.yml

See this annotation in the file changed.

Code scanning / zizmor

code injection via template expansion: may expand into attacker-controllable code Note

code injection via template expansion: may expand into attacker-controllable code

Check notice on line 33 in .github/workflows/workflow-lint.yml

See this annotation in the file changed.

Code scanning / zizmor

credential persistence through GitHub Actions artifacts: does not set persist-credentials: false Note

credential persistence through GitHub Actions artifacts: does not set persist-credentials: false

Check notice on line 48 in .github/workflows/workflow-lint.yml

See this annotation in the file changed.

Code scanning / zizmor

credential persistence through GitHub Actions artifacts: does not set persist-credentials: false Note

credential persistence through GitHub Actions artifacts: does not set persist-credentials: false