From ab411a5fdd6099696428cbf7898f459425daaada Mon Sep 17 00:00:00 2001 From: Douglas Eichelberger Date: Tue, 29 Sep 2026 13:21:17 -0700 Subject: [PATCH] Add zizmor and fix its findings Adds a zizmor workflow that calls rubyatscale/shared-config's reusable zizmor.yml, and fixes what zizmor 1.30.1 reports here so it starts clean. Every workflow here calls into shared-config, so there are no actions to pin. The @main calls into shared-config, secrets: inherit and the workflow_run CD trigger get the same documented zizmor ignores the other rubyatscale repos use. Dependabot entries get a 7-day cooldown. --- .github/dependabot.yml | 2 ++ .github/workflows/cd.yml | 4 ++-- .github/workflows/ci.yml | 2 +- .github/workflows/zizmor.yml | 16 ++++++++++++++++ 4 files changed, 21 insertions(+), 3 deletions(-) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 41acd66..8e30f0e 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,3 +9,5 @@ updates: labels: - "dependencies" - "github_actions" + cooldown: + default-days: 7 diff --git a/.github/workflows/cd.yml b/.github/workflows/cd.yml index 4c9ab97..57a2a16 100644 --- a/.github/workflows/cd.yml +++ b/.github/workflows/cd.yml @@ -1,6 +1,6 @@ name: CD -on: +on: # zizmor: ignore[dangerous-triggers] deploy-after-CI-passes is the standard rubyatscale release pattern; the called workflow only tags/publishes on main workflow_run: workflows: [CI] types: [completed] @@ -10,5 +10,5 @@ jobs: call-workflow-from-shared-config: permissions: contents: write - uses: rubyatscale/shared-config/.github/workflows/cd.yml@main + uses: rubyatscale/shared-config/.github/workflows/cd.yml@main # zizmor: ignore[unpinned-uses,secrets-inherit] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically; environments are managed by callers secrets: inherit diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3f7565f..feed61c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -10,5 +10,5 @@ jobs: call-workflow-from-shared-config: permissions: contents: read - uses: rubyatscale/shared-config/.github/workflows/ci.yml@main + uses: rubyatscale/shared-config/.github/workflows/ci.yml@main # zizmor: ignore[unpinned-uses,secrets-inherit] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically; its ci.yml reads SLACK_WEBHOOK_URL but declares no workflow_call secrets, so inherit is the only way to pass it secrets: inherit diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..e5a0721 --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,16 @@ +name: GitHub Actions Security Analysis + +on: + push: + branches: [main] + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + permissions: + contents: read + security-events: write + uses: rubyatscale/shared-config/.github/workflows/zizmor.yml@main # zizmor: ignore[unpinned-uses] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically