From 54598ee0372c898e833f7f963b462137daebe9dd Mon Sep 17 00:00:00 2001 From: Douglas Eichelberger Date: Tue, 29 Sep 2026 14:10:18 -0700 Subject: [PATCH] Add zizmor and fix its findings Adds a zizmor workflow that calls rubyatscale/shared-config's reusable zizmor.yml, and fixes what zizmor 1.30.1 reports here so it starts clean. Actions are pinned to commit SHAs with the version in a trailing comment: checkout at v7.0.1, as shared-config pins it, rustsec/audit-check at v2.0.0, and facebook/dotslash-publish-release at the commit its v1 tag points to, since it publishes no other tags. Checkouts set persist-credentials: false; the release jobs publish with gh and GH_TOKEN, not git push. The DotSlash job's condition mixed a bare expression with a ${{ }} interpolation, which GitHub evaluates as a non-empty string, so it was always true. It now checks needs.release.outputs.new_version directly. The release step reads the new version and SHA from env vars instead of expanding them into the script. There was no Dependabot config, so this adds one for github-actions only. --- .github/dependabot.yml | 12 ++++++++++++ .github/workflows/audit.yml | 6 ++++-- .github/workflows/ci.yml | 30 +++++++++++++++++++++--------- .github/workflows/zizmor.yml | 16 ++++++++++++++++ 4 files changed, 53 insertions(+), 11 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..274c097 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,12 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "monthly" + groups: + github-actions: + patterns: + - "*" + cooldown: + default-days: 7 diff --git a/.github/workflows/audit.yml b/.github/workflows/audit.yml index f937aaa..f997b21 100644 --- a/.github/workflows/audit.yml +++ b/.github/workflows/audit.yml @@ -25,7 +25,9 @@ jobs: env: RUSTUP_TOOLCHAIN: stable steps: - - uses: actions/checkout@v4 - - uses: rustsec/audit-check@v2.0.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: rustsec/audit-check@69366f33c96575abad1ee0dba8212993eecbe998 # v2.0.0 with: token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 355b537..c27fb2e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -26,7 +26,9 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout sources - uses: actions/checkout@v4 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Run cargo check run: cargo check @@ -35,7 +37,9 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout sources - uses: actions/checkout@v4 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Run cargo test with backtrace run: cargo test -- --nocapture @@ -48,7 +52,9 @@ jobs: RUSTFLAGS: "-Dwarnings" steps: - name: Checkout sources - uses: actions/checkout@v4 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Run cargo fmt run: cargo fmt --all -- --check @@ -69,8 +75,9 @@ jobs: changed: ${{ steps.check_for_version_changes.outputs.changed }} if: github.ref == 'refs/heads/main' steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: + persist-credentials: false # https://stackoverflow.com/questions/65944700/how-to-run-git-diff-in-github-actions # TLDR – By default this action fetches no history. # We need a bit of history to be able to check if we've recently updated the version in Cargo.toml @@ -100,9 +107,10 @@ jobs: - name: Create GitHub Release if current commit has updated the version in Cargo.toml if: steps.check_for_version_changes.outputs.changed == 'true' run: | - gh release create ${{steps.check_for_version_changes.outputs.new_version}} --target "${{ github.sha }}" --generate-notes + gh release create "$NEW_VERSION" --target "$GITHUB_SHA" --generate-notes env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + NEW_VERSION: ${{ steps.check_for_version_changes.outputs.new_version }} upload-mac-universal-bin: needs: release runs-on: macos-latest @@ -110,7 +118,9 @@ jobs: contents: write if: ${{needs.release.outputs.new_version}} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Build run: cargo build --release --target aarch64-apple-darwin --target x86_64-apple-darwin @@ -136,7 +146,9 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Update local toolchain run: | cargo install cross @@ -160,13 +172,13 @@ jobs: - release - upload-linux-bin - upload-mac-universal-bin - if: success() && ${{needs.release.outputs.new_version}} + if: success() && needs.release.outputs.new_version != '' runs-on: ubuntu-latest permissions: contents: write steps: - - uses: facebook/dotslash-publish-release@v1 + - uses: facebook/dotslash-publish-release@2539c4d8ae00a42773306c8731d2dd3724d979d2 # v1 # This is necessary because the action uses # `gh release upload` to publish the generated DotSlash file(s) # as part of the release. diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..e5a0721 --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,16 @@ +name: GitHub Actions Security Analysis + +on: + push: + branches: [main] + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + permissions: + contents: read + security-events: write + uses: rubyatscale/shared-config/.github/workflows/zizmor.yml@main # zizmor: ignore[unpinned-uses] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically