Skip to content

Use shared-config's reusable zizmor workflow - #121

Merged
dduugg merged 1 commit into
mainfrom
use-shared-zizmor
Sep 29, 2026
Merged

dduugg merged 1 commit into
mainfrom
use-shared-zizmor

Conversation

@dduugg

@dduugg dduugg commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Replaces this repo's copy of the zizmor workflow with a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32). zizmor-action bumps and fixes now land once in shared-config instead of in every repo, the same way #116 did for CodeQL.

  • Same behavior: the default advanced-security: true still uploads results to the Security tab, with the same triggers.
  • zizmor-action v0.6.2 → v0.6.4, the version shared-config pins (zizmor 1.30.1).
  • Permissions: the job grants contents: read and security-events: write. It drops actions: read, which upload-sarif only needs in private repos.
  • Check name is now zizmor / zizmor. No ruleset or branch protection requires the old zizmor name.

Test plan

  • actionlint is clean on the new workflow.
  • zizmor 1.30.0 (regular persona) reports no findings.
  • zizmor / zizmor runs on this PR and uploads to code scanning.

Replaces the copy of the zizmor workflow with a caller of
rubyatscale/shared-config/.github/workflows/zizmor.yml@main
(rubyatscale/shared-config#32), so zizmor-action bumps and fixes land
once in shared-config instead of in every repo.

It keeps the default advanced-security: true, so results still upload to
the Security tab and the same triggers apply. The job no longer requests
actions: read, which upload-sarif only needs in private repos. The check
is now named "zizmor / zizmor"; no ruleset requires the old name.
@dduugg
dduugg requested a review from a team as a code owner September 29, 2026 19:46
@dduugg
dduugg merged commit e49b8cb into main Sep 29, 2026
13 checks passed
@dduugg
dduugg deleted the use-shared-zizmor branch September 29, 2026 19:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant