Skip to content

Add zizmor and fix its findings - #136

Merged
dduugg merged 1 commit into
mainfrom
add-zizmor
Sep 29, 2026
Merged

dduugg merged 1 commit into
mainfrom
add-zizmor

Conversation

@dduugg

@dduugg dduugg commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds .github/workflows/zizmor.yml, a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32), and fixes everything zizmor 1.30.1 reports here so the new check starts clean. It's the same cleanup the other rubyatscale repos got this week.

  • zizmor mode: the default advanced-security: true, so results go to the Security tab. The caller grants contents: read and security-events: write.
  • Pinned to commit SHAs, with the version in a trailing comment:
    • actions/checkout v4 → v7.0.1 (7×), the version shared-config pins.
    • rustsec/audit-check v2.0.0.
    • facebook/dotslash-publish-release at the commit its v1 tag points to. It publishes no other tags, so the comment says v1.
  • persist-credentials: false on every checkout. The release jobs publish with gh and GH_TOKEN, not git push.
  • Always-true condition: the DotSlash job had if: success() && ${{needs.release.outputs.new_version}}. Mixing a bare expression with a ${{ }} interpolation makes GitHub evaluate it as a non-empty string, so it was always true (zizmor unsound-condition). It now reads success() && needs.release.outputs.new_version != ''.
  • Template injection: the release step read the new version and SHA through ${{ }} in its script. It now takes them from env vars.
  • Dependabot: there was no config, so this adds one for github-actions only (monthly, grouped, 7-day cooldown) to keep the new pins current.

This overlaps with the draft #128, which pins the same actions and fixes the same condition. Whichever merges second will need a rebase.

Test plan

  • zizmor 1.30.1 with online audits: 18 findings before, 0 after.
  • actionlint reports nothing new.
  • Fresh Eyes local review: no findings.
  • zizmor / zizmor and the existing checks pass on this PR.

Adds a zizmor workflow that calls rubyatscale/shared-config's reusable
zizmor.yml, and fixes what zizmor 1.30.1 reports here so it starts clean.

Actions are pinned to commit SHAs with the version in a trailing
comment: checkout at v7.0.1, as shared-config pins it, rustsec/audit-check
at v2.0.0, and facebook/dotslash-publish-release at the commit its v1 tag
points to, since it publishes no other tags. Checkouts set
persist-credentials: false; the release jobs publish with gh and
GH_TOKEN, not git push.

The DotSlash job's condition mixed a bare expression with a ${{ }}
interpolation, which GitHub evaluates as a non-empty string, so it was
always true. It now checks needs.release.outputs.new_version directly.
The release step reads the new version and SHA from env vars instead of
expanding them into the script.

There was no Dependabot config, so this adds one for github-actions only.
@dduugg
dduugg requested a review from a team as a code owner September 29, 2026 21:14
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@dduugg
dduugg merged commit bf7fc0a into main Sep 29, 2026
13 checks passed
@dduugg
dduugg deleted the add-zizmor branch September 29, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants