From 7f991332c785f51a79afe96de8a0a6ee1760f299 Mon Sep 17 00:00:00 2001 From: Douglas Eichelberger Date: Tue, 29 Sep 2026 13:21:15 -0700 Subject: [PATCH] Add zizmor and fix its findings Adds a zizmor workflow that calls rubyatscale/shared-config's reusable zizmor.yml, and fixes what zizmor 1.30.1 reports here so it starts clean. Actions are pinned to commit SHAs with the exact version in a trailing comment: checkout at v7.0.1, as shared-config pins it, and the rest at the release their floating tag runs today. Checkouts set persist-credentials: false. The @main calls into shared-config get the same documented zizmor ignores the other rubyatscale repos use. Dependabot entries get a 7-day cooldown, and a github-actions entry keeps the new pins current. The gem release no longer restores the bundler cache, which other workflows can write; it runs bundle install instead. --- .github/dependabot.yml | 12 ++++++++++++ .github/workflows/ci.yml | 8 ++++++-- .github/workflows/push_gem.yml | 12 ++++++++---- .github/workflows/zizmor.yml | 16 ++++++++++++++++ 4 files changed, 42 insertions(+), 6 deletions(-) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 09f4568..3239b02 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -8,3 +8,15 @@ updates: bundler: patterns: - "*" + cooldown: + default-days: 7 + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "monthly" + groups: + github-actions: + patterns: + - "*" + cooldown: + default-days: 7 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index dfeadec..b16a36d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -23,8 +23,10 @@ jobs: name: "Tests: Ruby ${{ matrix.ruby }}" steps: - uses: actions/checkout@5126516654c75f76bca1de45dd82a3006d8890f9 + with: + persist-credentials: false - name: Set up Ruby ${{ matrix.ruby }} - uses: ruby/setup-ruby@v1 + uses: ruby/setup-ruby@14594264cd68ce8a2345dd349bc3d138a4ef85c8 # v1.327.0 with: bundler-cache: true ruby-version: ${{ matrix.ruby }} @@ -35,8 +37,10 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@5126516654c75f76bca1de45dd82a3006d8890f9 + with: + persist-credentials: false - name: Rubyfmt - uses: rubyatscale/rubyfmt-action@v1 + uses: rubyatscale/rubyfmt-action@cf0cfc65bb8cab4c628ffea8662892598a48d6d3 # v1.0.0 with: paths: | lib/ diff --git a/.github/workflows/push_gem.yml b/.github/workflows/push_gem.yml index 8f921f6..06864c5 100644 --- a/.github/workflows/push_gem.yml +++ b/.github/workflows/push_gem.yml @@ -17,12 +17,16 @@ jobs: steps: # Set up - - uses: actions/checkout@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Set up Ruby - uses: ruby/setup-ruby@v1 + uses: ruby/setup-ruby@14594264cd68ce8a2345dd349bc3d138a4ef85c8 # v1.327.0 with: - bundler-cache: true ruby-version: ruby + # Not bundler-cache: a tag-triggered release shouldn't restore a cache other workflows can write. + - name: Install gems + run: bundle install # Release - - uses: rubygems/release-gem@v1 + - uses: rubygems/release-gem@7f9650160c1a4e7989fdc9855807bdbd421d8b6b # v1.4.1 diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..e5a0721 --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,16 @@ +name: GitHub Actions Security Analysis + +on: + push: + branches: [main] + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + permissions: + contents: read + security-events: write + uses: rubyatscale/shared-config/.github/workflows/zizmor.yml@main # zizmor: ignore[unpinned-uses] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically