Skip to content

Use shared-config's reusable zizmor workflow - #8

Merged
dduugg merged 1 commit into
mainfrom
use-shared-zizmor
Sep 29, 2026
Merged

dduugg merged 1 commit into
mainfrom
use-shared-zizmor

Conversation

@dduugg

@dduugg dduugg commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Replaces this repo's copy of the zizmor workflow with a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32). zizmor-action bumps and fixes now land once in shared-config instead of in every repo.

  • Same behavior: the default advanced-security: true still uploads results to the Security tab, with the same triggers.
  • zizmor-action v0.6.3 → v0.6.4, the version shared-config pins (zizmor 1.30.1).
  • Permissions: the job grants contents: read and security-events: write. It drops actions: read, which upload-sarif only needs in private repos.
  • Check name is now zizmor / zizmor. No ruleset or branch protection requires the old zizmor name.

Test plan

  • actionlint is clean on the new workflow.
  • zizmor 1.30.0 (regular persona) reports no findings.
  • zizmor / zizmor runs on this PR and uploads to code scanning.

Replaces the copy of the zizmor workflow with a caller of
rubyatscale/shared-config/.github/workflows/zizmor.yml@main
(rubyatscale/shared-config#32), so zizmor-action bumps and fixes land
once in shared-config instead of in every repo.

It keeps the default advanced-security: true, so results still upload to
the Security tab and the same triggers apply. The job no longer requests
actions: read, which upload-sarif only needs in private repos. The check
is now named "zizmor / zizmor"; no ruleset requires the old name.

This moves zizmor-action from v0.6.3 to v0.6.4, the version shared-config
pins.
@dduugg
dduugg merged commit f86ac93 into main Sep 29, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant