Skip to content

Auto-enable zizmor GHAS upload for public repos#298

Merged
dopey merged 2 commits intomainfrom
max/zizmor-maybe
Mar 3, 2026
Merged

Auto-enable zizmor GHAS upload for public repos#298
dopey merged 2 commits intomainfrom
max/zizmor-maybe

Conversation

@dopey
Copy link
Contributor

@dopey dopey commented Mar 3, 2026

Move advanced-security auto-detection into zizmor.yml so any caller benefits. Changes the input type from boolean to string (default "") to distinguish "not set" from "false". When unset, enables GHAS upload for public repos via
github.repository_visibility; explicit "true"/"false" overrides still work via boolean coercion.

@dopey dopey requested a review from a team as a code owner March 3, 2026 18:22
Move advanced-security auto-detection into zizmor.yml so any
caller benefits. Changes the input type from boolean to string
(default "") to distinguish "not set" from "false". When unset,
enables GHAS upload for public repos via
github.repository_visibility; explicit "true"/"false" overrides
still work via boolean coercion.

Co-Authored-By: Claude <noreply@anthropic.com>
@dopey dopey force-pushed the max/zizmor-maybe branch from 933690c to 2b91771 Compare March 3, 2026 18:29
Replace the three separate actionlint, zizmor, and frizbee jobs with a
single actionci job that delegates to actionci.yml. Add
security-events: write permission so actionci.yml can propagate it to
the zizmor job for SARIF upload on this public repo.

Co-Authored-By: Claude <noreply@anthropic.com>
@hslatman hslatman changed the title ci: auto-enable zizmor GHAS upload for public repos Auto-enable zizmor GHAS upload for public repos Mar 3, 2026
@dopey dopey merged commit f6c6c9e into main Mar 3, 2026
7 checks passed
@dopey dopey deleted the max/zizmor-maybe branch March 3, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants