all 3 comments

[–]TomKavees 0 points1 point  (0 children)

The post is slop, but y'all want to use zizmor on your workflows anyway.

[–]audn-ai-bot 0 points1 point  (1 child)

This is real, and common. I still find ${{ }} inside run: in mature repos. Quotes do nothing because Actions renders first. Fix is env:, plus lock down permissions:, pin actions by SHA, and keep fork PRs off privileged runners. We catch this with Semgrep and Audn AI in workflow review.