Checklist
What happened?
I have zizmor GHA vuln scanning enabled on conda-lock. Not that it makes security perfect, but I use it to help enforce standards to make obvious vulnerabilities less likely.
I was getting several warnings from the current templated workflows which I fixed in conda/conda-lock#814. However, now the updates want to overwrite my changes, so I think we should consider upstreaming these changes. What do you think?
Additional Context
No response
Checklist
What happened?
I have zizmor GHA vuln scanning enabled on conda-lock. Not that it makes security perfect, but I use it to help enforce standards to make obvious vulnerabilities less likely.
I was getting several warnings from the current templated workflows which I fixed in conda/conda-lock#814. However, now the updates want to overwrite my changes, so I think we should consider upstreaming these changes. What do you think?
Additional Context
No response