Skip to content

ci: Add actionci.yml#1578

Merged
dopey merged 7 commits intomasterfrom
max/add-zizmor-frizbee
Mar 3, 2026
Merged

ci: Add actionci.yml#1578
dopey merged 7 commits intomasterfrom
max/add-zizmor-frizbee

Conversation

@dopey
Copy link
Contributor

@dopey dopey commented Mar 3, 2026

No description provided.

tashian and others added 6 commits March 2, 2026 17:45
Add caller workflows for zizmor (security scanning) and frizbee
(action pinning verification). Fix zizmor findings where applicable
and add suppression config for intentional patterns.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Use unpinned-uses config.policies with org-level wildcard and
secrets-inherit disable instead of brittle per-line ignores that
break whenever workflow files change.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The ref-confusion audit crashes when workflows reference private
repos (e.g. internal-workflows, robot) because the GITHUB_TOKEN
lacks cross-repo access. Disable until zizmor supports scoping
this audit or we provide a broader token.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The caller workflow's permissions are the ceiling for reusable
workflows. The zizmor-action needs security-events: write to
upload SARIF results to GitHub Advanced Security.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions github-actions bot added the needs triage Waiting for discussion / prioritization by team label Mar 3, 2026
@dopey dopey merged commit 4fbbd94 into master Mar 3, 2026
6 checks passed
@dopey dopey deleted the max/add-zizmor-frizbee branch March 3, 2026 03:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs triage Waiting for discussion / prioritization by team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants