Mirrored from GitHub github.com/roostorg/coop

ci: use zizmor to lint for CI security issues (#721) master

* Harden GitHub Actions workflows per zizmor audit Fix zizmor findings across the workflows: - Move `github.base_ref`/`inputs.ref`/step-output expressions out of `run:` blocks into `env:` vars to avoid template injection. - Scope `checks: write` down from the workflow level to only the `check_api_server` job in apply_pr_checks.yaml. - Add `persist-credentials: false` to checkout steps. - Add a zizmor CI workflow to run the audit on push and PRs. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * mdbook: drop broken cache step, install binary unconditionally zizmor's cache-poisoning auto-fix added `lookup-only: true` to the mdbook cache step. Because the install step was gated on `cache-hit != 'true'`, a cache hit then skipped both the download and the install, leaving mdbook-bin/ empty and breaking the build. The original win (PR #14 / issue #3) was switching from compiling mdbook from source to downloading the prebuilt release; the cache was only a marginal optimization on top. Removing it keeps that win, fixes the break, and resolves the cache-poisoning finding cleanly. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * address PR comments * ignore dependabot cooldowns in zizmor * add dependency cooldown to dependabot --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>