Add zizmor and fix its findings - #136
Merged
Merged
Conversation
Adds a zizmor workflow that calls rubyatscale/shared-config's reusable
zizmor.yml, and fixes what zizmor 1.30.1 reports here so it starts clean.
Actions are pinned to commit SHAs with the version in a trailing
comment: checkout at v7.0.1, as shared-config pins it, rustsec/audit-check
at v2.0.0, and facebook/dotslash-publish-release at the commit its v1 tag
points to, since it publishes no other tags. Checkouts set
persist-credentials: false; the release jobs publish with gh and
GH_TOKEN, not git push.
The DotSlash job's condition mixed a bare expression with a ${{ }}
interpolation, which GitHub evaluates as a non-empty string, so it was
always true. It now checks needs.release.outputs.new_version directly.
The release step reads the new version and SHA from env vars instead of
expanding them into the script.
There was no Dependabot config, so this adds one for github-actions only.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
.github/workflows/zizmor.yml, a caller ofrubyatscale/shared-config/.github/workflows/zizmor.yml@main(rubyatscale/shared-config#32), and fixes everything zizmor 1.30.1 reports here so the new check starts clean. It's the same cleanup the other rubyatscale repos got this week.advanced-security: true, so results go to the Security tab. The caller grantscontents: readandsecurity-events: write.actions/checkoutv4 → v7.0.1 (7×), the version shared-config pins.rustsec/audit-checkv2.0.0.facebook/dotslash-publish-releaseat the commit itsv1tag points to. It publishes no other tags, so the comment saysv1.persist-credentials: falseon every checkout. The release jobs publish withghandGH_TOKEN, notgit push.if: success() && ${{needs.release.outputs.new_version}}. Mixing a bare expression with a${{ }}interpolation makes GitHub evaluate it as a non-empty string, so it was always true (zizmorunsound-condition). It now readssuccess() && needs.release.outputs.new_version != ''.${{ }}in its script. It now takes them from env vars.github-actionsonly (monthly, grouped, 7-day cooldown) to keep the new pins current.This overlaps with the draft #128, which pins the same actions and fixes the same condition. Whichever merges second will need a rebase.
Test plan
zizmor / zizmorand the existing checks pass on this PR.