chore(actions): resolve zizmor findings that block workflow PRs - #28043
Merged
Merged
Conversation
The org "GitHub Actions Scan" check scans every workflow file a PR
touches in full, evaluates mandatory rules against a --no-ignores
report, and fails on any Medium or High finding. Two pre-existing
findings in ci.yml therefore block every PR that edits it:
- template-injection (mandatory): ${{ github.event_path }} was expanded
inside `run:`. Read the runner's GITHUB_EVENT_NAME / GITHUB_EVENT_PATH
instead, under `shell: bash`, because the windows-latest default shell
(pwsh) does not expand "${VAR}" from the environment and toys ci would
silently fall back to "No base SHA" and test nothing. Drop the ignore
comments, which the scan no longer honors for mandatory rules.
- ref-version-mismatch (medium): checkout pin comments named major tags
that no longer point at the pinned SHAs. Correct them to v2.7.0 and
v4.3.1 across all five workflows. The SHAs themselves are unchanged.
quartzmo
approved these changes
Sep 28, 2026
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two pre-existing zizmor findings in
ci.ymlfail the org GitHub Actions Scan for any PR that edits the file, e.g. #28002, whose only workflow change drops the Ruby 3.2 row:${{ github.event_path }}inrun:. The step now reads the runner'sGITHUB_EVENT_*variables undershell: bash, so the Windows leg (defaultpwsh) still expands them.v2.7.0/v4.3.1in all five workflows; SHAs unchanged.Checked locally with the scan's pinned zizmor 1.25.2: no findings.