ci: pin containers to digest, enable more zizmor rules (#38779)

Enable more strict "pedantic" zizmor rules and fix issues. Service
containers are pinned to hash and renovate will update them. Enabled
rules:

- https://docs.zizmor.sh/audits/#excessive-permissions
- https://docs.zizmor.sh/audits/#unpinned-images
- https://docs.zizmor.sh/audits/#template-injection

---------

Signed-off-by: silverwind <me@silverwind.io>
This commit is contained in:
silverwind
2026-08-06 05:16:07 +00:00
committed by GitHub
parent d94f714efa
commit d8c3a1afda
14 changed files with 47 additions and 20 deletions
+4
View File
@@ -100,6 +100,10 @@
"matchPackageNames": ["mcr.microsoft.com/mssql/server"],
"allowedVersions": "/^2019($|[.-])/", // pin to oldest in extended support
},
{
"matchPackageNames": ["docker.elastic.co/elasticsearch/elasticsearch"],
"allowedVersions": "/^8($|[.-])/", // pin to oldest supported major
},
{
"matchManagers": ["gomod"],
"postUpdateOptions": ["gomodUpdateImportPaths"],