Introducing zizmor: now you can have beautiful clean workflows
Related
More from ENOSUCHBLOG
I’m not aware of a perfect1 term for this, so I’m making one up: the Makefile effect2. The Makefile effect resembles other phenomena, like cargo culting, normalization of deviance, “write-only language,” &c. I’ll argue in this post that it’s a little different from each of these, insofar as it’s not inherently ineffective or bad and concerns the...
TL;DR: zizmor would have caught the vulnerability that caused this…mostly. Read on for details.
Standard disclaimer: These are my personal opinions, not the opinions of my employer, PyPI, or any open source I projects I participate in (either for funsies or because I’m paid to). In particular, nothing I write below can be interpreted to imply (or imply the negation of) similar opinions by any of the above, except where explicitly stated.
Another Rust crate announcement: this time I’m announcing yamlpath, a small library for format-preserving YAML feature extraction.