Skip to content

chore(actions): resolve zizmor findings that block workflow PRs - #28043

Merged
torreypayne merged 1 commit into
mainfrom
chore/zizmor-workflow-findings
Sep 28, 2026
Merged

torreypayne merged 1 commit into
mainfrom
chore/zizmor-workflow-findings

Conversation

@torreypayne

Copy link
Copy Markdown
Member

Two pre-existing zizmor findings in ci.yml fail the org GitHub Actions Scan for any PR that edits the file, e.g. #28002, whose only workflow change drops the Ruby 3.2 row:

  • template-injection (mandatory, so ignore comments don't count): ${{ github.event_path }} in run:. The step now reads the runner's GITHUB_EVENT_* variables under shell: bash, so the Windows leg (default pwsh) still expands them.
  • ref-version-mismatch: checkout pin comments named major tags. Corrected to v2.7.0 / v4.3.1 in all five workflows; SHAs unchanged.

Checked locally with the scan's pinned zizmor 1.25.2: no findings.

The org "GitHub Actions Scan" check scans every workflow file a PR
touches in full, evaluates mandatory rules against a --no-ignores
report, and fails on any Medium or High finding. Two pre-existing
findings in ci.yml therefore block every PR that edits it:

- template-injection (mandatory): ${{ github.event_path }} was expanded
  inside `run:`. Read the runner's GITHUB_EVENT_NAME / GITHUB_EVENT_PATH
  instead, under `shell: bash`, because the windows-latest default shell
  (pwsh) does not expand "${VAR}" from the environment and toys ci would
  silently fall back to "No base SHA" and test nothing. Drop the ignore
  comments, which the scan no longer honors for mandatory rules.
- ref-version-mismatch (medium): checkout pin comments named major tags
  that no longer point at the pinned SHAs. Correct them to v2.7.0 and
  v4.3.1 across all five workflows. The SHAs themselves are unchanged.
@torreypayne
torreypayne requested a review from a team as a code owner September 25, 2026 22:06
@torreypayne
torreypayne merged commit d089246 into main Sep 28, 2026
15 checks passed
@torreypayne
torreypayne deleted the chore/zizmor-workflow-findings branch September 28, 2026 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants