Skip to content

ci: keep push scans green when the scan moves to Zizmor 1.30.1 - #91

Merged
altaywtf merged 1 commit into
mainfrom
ci/zizmor-self-repository
Oct 5, 2026
Merged

altaywtf merged 1 commit into
mainfrom
ci/zizmor-self-repository

Conversation

@altaywtf

@altaywtf altaywtf commented Oct 5, 2026

Copy link
Copy Markdown
Member

Once the shared scan moves to Zizmor 1.30.1 (putdotio/.github#9), its new self-repository audit flags Release's call to the CI workflow and turns push scans on main red. That uses: ./.github/workflows/ci.yml line now ends with # zizmor: ignore[self-repository], the form putdotio/.github already uses.

Zizmor main This PR
1.29.0, the live scan clean clean, identical output
1.30.1 1 self-repository finding clean
  • A ci: commit releases nothing: the merge runs CI's verify and the scan, publishes no ZIP, and deploys nothing to roku.put.io.
  • The Zizmor runs above are local, online audits included; the scan passes through pull requests. Actionlint 1.7.12 is clean, and pnpm verify doesn't read workflow files.

Written by an agent (Claude Code, Claude Opus 5.5)

Copilot AI balanced review requested due to automatic review settings October 5, 2026 08:52
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

It is a single, correctly-formatted lint-suppression comment on a verified in-repo reusable-workflow call with no functional or runtime impact.

Review effort: Balanced
Findings: None

What changed in this PR

This PR adds a # zizmor: ignore[self-repository] suppression comment to Release's reusable-workflow call so that push scans on main stay green once the shared scan (putdotio/.github) upgrades to Zizmor 1.30.1, which introduces a new self-repository audit that would otherwise flag uses: ./.github/workflows/ci.yml.

Changes:

  • Appended # zizmor: ignore[self-repository] to the verify job's uses: line in release.yml.
File Description
.github/​workflows/​release.yml Suppresses the forthcoming Zizmor self-repository finding on the local reusable-workflow call (uses: ./.github/workflows/ci.yml).

I verified that ci.yml is a reusable workflow (on: workflow_call) called in-repo from release.yml, which is exactly what the self-repository audit targets; the ignore-comment syntax and end-of-line placement match Zizmor's documented form and the pattern noted in the PR description. The change has no runtime effect under the currently pinned Zizmor and only suppresses the finding after the shared scan upgrades, so it is safe either way. No issues were found.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@altaywtf
altaywtf merged commit b53df95 into main Oct 5, 2026
2 checks passed
@altaywtf
altaywtf deleted the ci/zizmor-self-repository branch October 5, 2026 09:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants