We should consider a tool like https://github.com/zizmorcore/zizmor for running security analysis on our github actions workflows