Skip to content

Make zizmor.yml a reusable workflow_call workflow - #32

Merged
dduugg merged 4 commits into
mainfrom
add-reusable-zizmor
Sep 29, 2026
Merged

dduugg merged 4 commits into
mainfrom
add-reusable-zizmor

Conversation

@dduugg

@dduugg dduugg commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

zizmor.yml becomes a workflow_call workflow, so gem repos can call zizmor from here instead of each keeping its own copy. This follows what #29 did for codeql.yml.

  • zizmor-self-scan.yml keeps the push and PR triggers and calls $/.github/workflows/zizmor.yml, GitHub's self-repository syntax. shared-config still scans itself and uploads to the Security tab as before. $/ resolves to the commit that is running, so a PR that edits zizmor.yml is tested against its own version. codeql-self-scan.yml switches from ./ to $/ too: zizmor 1.30's self-repository audit flags ./, and the v0.6.4 bump below would otherwise add that alert on main.
  • advanced-security input (boolean, default true, zizmor-action's default):
    • true uploads the results to the Security tab, as the current workflow does.
    • false reports findings as annotations and fails the job.
    • A required check needs false, because zizmor exits 0 whenever it writes SARIF. I checked locally: zizmor 1.30.0 on a workflow with findings exits 0 with --format sarif and 14 with --format github.
  • No permissions block on the job. The two modes need different permissions, and a reusable workflow's job can't ask for more than its caller grants, so it takes the caller's. The README lists what each mode needs. ci.yml and cd.yml do the same.
  • The README moves zizmor into the reusable-workflows table and adds a caller example. It names the check to require (zizmor / zizmor with the example) and notes that callers tracking @main pick up zizmor-action upgrades, and any new audits, at once.
  • CodeQL docs. Make codeql.yml a reusable workflow_call workflow #29 never added codeql.yml or codeql-self-scan.yml to the README. Both are now in the tables, with a caller example and the languages input.
  • zizmor-action goes to v0.6.4 (zizmor 1.30.1). v0.6.2 still ran 1.29.0, and rubyfmt-action is already on v0.6.3, so moving it onto this workflow would otherwise have been a downgrade. action.sh is the same in both versions.

The first caller will be rubyatscale/singed, which will use advanced-security: false so zizmor can be a required check there.

Test plan

  • actionlint is clean apart from the two $/ calls, which actionlint 1.7.12 doesn't recognize yet (Support the new $/ self-repository uses: syntax rhysd/actionlint#711).
  • zizmor (regular persona) reports no findings.
  • Both self-scans run on this PR through $/, and the zizmor scan uploads to code scanning. The self-repository alerts (#44, #45) show as fixed.

Gem repos can now call zizmor from here instead of carrying their own copy,
as codeql.yml did in #29. zizmor-self-scan.yml keeps the push and PR
triggers and calls it locally, so shared-config still scans itself, with
the same Security tab upload as before.

The advanced-security input defaults to true, the zizmor-action default.
Setting it to false reports findings as annotations and fails the job,
which a required check needs: zizmor exits 0 whenever it writes SARIF.
The job has no permissions block so that it takes the caller's, since
the two modes need different ones.
@dduugg
dduugg requested a review from a team as a code owner September 29, 2026 18:51
@github-project-automation github-project-automation Bot moved this to Triage in Modularity Sep 29, 2026
v0.6.4 makes zizmor 1.30.1 the default. The v0.6.2 pin still ran 1.29.0,
and rubyfmt-action is already on v0.6.3, so moving it onto this workflow
would otherwise be a downgrade. action.sh is unchanged between the two;
action.yml only bumps its upload-sarif pin.
The README never picked up codeql.yml or codeql-self-scan.yml from #29.
Both are now in the tables, with a caller example and the languages
input.

The zizmor section now names the check to require (zizmor / zizmor with
the example), notes that actions: read is only needed in private repos,
and warns that callers tracking @main pick up zizmor-action upgrades,
and any new audits, at once. The job comment in zizmor.yml now says what
callers should grant instead of reading as a guarantee.
Comment thread .github/workflows/zizmor-self-scan.yml Fixed
zizmor 1.30 (now the default via zizmor-action v0.6.4) flags ./ calls
to in-repo workflows with its self-repository audit. $/ resolves to this
repository at the commit that is running, like ./ does, so a PR that
edits zizmor.yml or codeql.yml is still tested against its own version.
GitHub also treats $/ references as pinned under the policy requiring
full-length SHA pins, which ./ references are not.

codeql-self-scan.yml gets the same change, since it would otherwise gain
the same alert on main once this merges.

actionlint 1.7.12 doesn't recognize $/ yet (rhysd/actionlint#711).
@dduugg
dduugg merged commit 9d489e4 into main Sep 29, 2026
4 checks passed
@dduugg
dduugg deleted the add-reusable-zizmor branch September 29, 2026 19:25
dduugg added a commit to rubyatscale/visualize_packs that referenced this pull request Sep 29, 2026
Replaces the copy of the zizmor workflow with a caller of
rubyatscale/shared-config/.github/workflows/zizmor.yml@main
(rubyatscale/shared-config#32), so zizmor-action bumps and fixes land
once in shared-config instead of in every repo.

It keeps the default advanced-security: true, so results still upload to
the Security tab and the same triggers apply. The job no longer requests
actions: read, which upload-sarif only needs in private repos. The check
is now named "zizmor / zizmor"; no ruleset requires the old name.
dduugg added a commit to rubyatscale/pks that referenced this pull request Sep 29, 2026
Replaces the copy of the zizmor workflow with a caller of
rubyatscale/shared-config/.github/workflows/zizmor.yml@main
(rubyatscale/shared-config#32), so zizmor-action bumps and fixes land
once in shared-config instead of in every repo.

It keeps the default advanced-security: true, so results still upload to
the Security tab and the same triggers apply. The job no longer requests
actions: read, which upload-sarif only needs in private repos. The check
is now named "zizmor / zizmor"; no ruleset requires the old name.

.github/zizmor.yml still applies: zizmor finds it in the checked-out repo,
as before.
dduugg added a commit to rubyatscale/rubyfmt-action that referenced this pull request Sep 29, 2026
Replaces the copy of the zizmor workflow with a caller of
rubyatscale/shared-config/.github/workflows/zizmor.yml@main
(rubyatscale/shared-config#32), so zizmor-action bumps and fixes land
once in shared-config instead of in every repo.

It keeps the default advanced-security: true, so results still upload to
the Security tab and the same triggers apply. The job no longer requests
actions: read, which upload-sarif only needs in private repos. The check
is now named "zizmor / zizmor"; no ruleset requires the old name.

This moves zizmor-action from v0.6.3 to v0.6.4, the version shared-config
pins.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants