Address https://docs.zizmor.sh/audits/#artipacked findings. - #3081
Merged
Conversation
Google has been rolling out `zizmor` to more of its repos, and `zizmor` wants `persist-credentials: false`. (Gemini leads me to believe that the risk without `persist-credentials: false` has been minimal since [version 6](https://github.com/actions/checkout/releases/tag/v6.0.0) (actions/checkout#2286?). I haven't tried to verify that. It [doesn't seem like the default `persist-credentials` value is likely to change](actions/checkout#485).) `zizmor` also wants us to pin `google/oss-fuzz`. I posted google/oss-fuzz#6836 (comment).
eamonnmcmanus
approved these changes
Aug 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Google has been rolling out
zizmorto more of its repos, andzizmorwantspersist-credentials: false.(Gemini leads me to believe that the risk without
persist-credentials: falsehas been minimal since version 6 (actions/checkout#2286?). I haven't tried to verify that. It doesn't seem like the defaultpersist-credentialsvalue is likely to change.)zizmoralso wants us to pingoogle/oss-fuzz. I posted google/oss-fuzz#6836 (comment).Purpose
Description
Checklist
This is automatically checked by
mvn verify, but can also be checked on its own usingmvn spotless:check.Style violations can be fixed using
mvn spotless:apply; this can be done in a separate commit to verify that it did not cause undesired changes.null@since $next-version$(
$next-version$is a special placeholder which is automatically replaced during release)TestCase)mvn clean verify javadoc:jarpasses without errors