Skip to content

ci: report Java to Kotlin migration progress on pull requests #56

ci: report Java to Kotlin migration progress on pull requests

ci: report Java to Kotlin migration progress on pull requests #56

Triggered via pull request October 6, 2026 21:50
Status Success
Total duration 21s
Artifacts –

zizmor.yml

on: pull_request
Scan GitHub Actions workflows
15s
Scan GitHub Actions workflows
Fit to window
Zoom out
Zoom in

Annotations

10 errors, 10 warnings, and 10 notices
excessive-permissions: .github/workflows/pull-request.yml#L18
pull-request.yml:18: overly broad permissions: id-token: write is overly broad at the workflow level
unpinned-uses: .github/workflows/issue-autorespond-and-close.yml#L14
issue-autorespond-and-close.yml:14: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/instrumented-tests.yml#L67
instrumented-tests.yml:67: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/dependabot-automerge.yml#L17
dependabot-automerge.yml:17: unpinned action reference: action is not pinned to a hash (required by blanket policy)
dangerous-triggers: .github/workflows/dependabot-automerge.yml#L3
dependabot-automerge.yml:3: use of fundamentally insecure workflow trigger: workflow_run is almost always used insecurely
unpinned-uses: .github/workflows/daily.yml#L301
daily.yml:301: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/daily.yml#L295
daily.yml:295: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/daily.yml#L256
daily.yml:256: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/daily.yml#L250
daily.yml:250: unpinned action reference: action is not pinned to a hash (required by blanket policy)
unpinned-uses: .github/workflows/daily.yml#L211
daily.yml:211: unpinned action reference: action is not pinned to a hash (required by blanket policy)
artipacked: .github/workflows/daily.yml#L317
daily.yml:317: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
artipacked: .github/workflows/daily.yml#L268
daily.yml:268: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
artipacked: .github/workflows/daily.yml#L223
daily.yml:223: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
artipacked: .github/workflows/daily.yml#L194
daily.yml:194: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
artipacked: .github/workflows/daily.yml#L47
daily.yml:47: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
artipacked: .github/workflows/build-kits.yml#L71
build-kits.yml:71: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
artipacked: .github/workflows/build-kits.yml#L30
build-kits.yml:30: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
artipacked: .github/workflows/build-kits.yml#L17
build-kits.yml:17: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
dependabot-cooldown: .github/dependabot.yml#L23
dependabot.yml:23: insufficient cooldown in Dependabot updates: insufficient implicit default-days (less than 7)
dependabot-cooldown: .github/dependabot.yml#L3
dependabot.yml:3: insufficient cooldown in Dependabot updates: insufficient implicit default-days (less than 7)
template-injection: .github/workflows/release-publish.yml#L69
release-publish.yml:69: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-publish.yml#L66
release-publish.yml:66: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-publish.yml#L63
release-publish.yml:63: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-draft.yml#L131
release-draft.yml:131: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-draft.yml#L128
release-draft.yml:128: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-draft.yml#L125
release-draft.yml:125: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-draft.yml#L122
release-draft.yml:122: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-draft.yml#L119
release-draft.yml:119: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-draft.yml#L116
release-draft.yml:116: code injection via template expansion: may expand into attacker-controllable code
template-injection: .github/workflows/release-draft.yml#L113
release-draft.yml:113: code injection via template expansion: may expand into attacker-controllable code