Repository navigation
ci: keep push scans green when the scan moves to Zizmor 1.30.1 - #91
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
It is a single, correctly-formatted lint-suppression comment on a verified in-repo reusable-workflow call with no functional or runtime impact.
Review effort: Balanced
Findings: None
What changed in this PR
This PR adds a # zizmor: ignore[self-repository] suppression comment to Release's reusable-workflow call so that push scans on main stay green once the shared scan (putdotio/.github) upgrades to Zizmor 1.30.1, which introduces a new self-repository audit that would otherwise flag uses: ./.github/workflows/ci.yml.
Changes:
- Appended
# zizmor: ignore[self-repository]to theverifyjob'suses:line inrelease.yml.
| File | Description |
|---|---|
| .github/workflows/release.yml | Suppresses the forthcoming Zizmor self-repository finding on the local reusable-workflow call (uses: ./.github/workflows/ci.yml). |
I verified that ci.yml is a reusable workflow (on: workflow_call) called in-repo from release.yml, which is exactly what the self-repository audit targets; the ignore-comment syntax and end-of-line placement match Zizmor's documented form and the pattern noted in the PR description. The change has no runtime effect under the currently pinned Zizmor and only suppresses the finding after the shared scan upgrades, so it is safe either way. No issues were found.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Once the shared scan moves to Zizmor 1.30.1 (putdotio/.github#9), its new
self-repositoryaudit flags Release's call to the CI workflow and turns push scans onmainred. Thatuses: ./.github/workflows/ci.ymlline now ends with# zizmor: ignore[self-repository], the form putdotio/.github already uses.mainself-repositoryfindingci:commit releases nothing: the merge runs CI's verify and the scan, publishes no ZIP, and deploys nothing to roku.put.io.pnpm verifydoesn't read workflow files.Written by an agent (Claude Code, Claude Opus 5.5)