use zizmor for scanning gh workflow files #88
thebigbone
started this conversation in
Ideas
Replies: 1 comment
-
|
Hello there and thanks for your suggestions! I'll take a look into zizmor or similar. What's the benefit of polarix compared to a distroless setup? Cheers! |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Thanks for this image with good security configurations. I was wondering if it would be beneficial to scan the workflow yamls with https://github.com/woodruffw/zizmor.
PS: you should checkout polarix-containers, they are also creating secure container images.
Beta Was this translation helpful? Give feedback.
All reactions