Make zizmor.yml a reusable workflow_call workflow - #32
Merged
Merged
Conversation
Gem repos can now call zizmor from here instead of carrying their own copy, as codeql.yml did in #29. zizmor-self-scan.yml keeps the push and PR triggers and calls it locally, so shared-config still scans itself, with the same Security tab upload as before. The advanced-security input defaults to true, the zizmor-action default. Setting it to false reports findings as annotations and fails the job, which a required check needs: zizmor exits 0 whenever it writes SARIF. The job has no permissions block so that it takes the caller's, since the two modes need different ones.
v0.6.4 makes zizmor 1.30.1 the default. The v0.6.2 pin still ran 1.29.0, and rubyfmt-action is already on v0.6.3, so moving it onto this workflow would otherwise be a downgrade. action.sh is unchanged between the two; action.yml only bumps its upload-sarif pin.
The README never picked up codeql.yml or codeql-self-scan.yml from #29. Both are now in the tables, with a caller example and the languages input. The zizmor section now names the check to require (zizmor / zizmor with the example), notes that actions: read is only needed in private repos, and warns that callers tracking @main pick up zizmor-action upgrades, and any new audits, at once. The job comment in zizmor.yml now says what callers should grant instead of reading as a guarantee.
zizmor 1.30 (now the default via zizmor-action v0.6.4) flags ./ calls to in-repo workflows with its self-repository audit. $/ resolves to this repository at the commit that is running, like ./ does, so a PR that edits zizmor.yml or codeql.yml is still tested against its own version. GitHub also treats $/ references as pinned under the policy requiring full-length SHA pins, which ./ references are not. codeql-self-scan.yml gets the same change, since it would otherwise gain the same alert on main once this merges. actionlint 1.7.12 doesn't recognize $/ yet (rhysd/actionlint#711).
This was referenced Sep 29, 2026
dduugg
added a commit
to rubyatscale/visualize_packs
that referenced
this pull request
Sep 29, 2026
Replaces the copy of the zizmor workflow with a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32), so zizmor-action bumps and fixes land once in shared-config instead of in every repo. It keeps the default advanced-security: true, so results still upload to the Security tab and the same triggers apply. The job no longer requests actions: read, which upload-sarif only needs in private repos. The check is now named "zizmor / zizmor"; no ruleset requires the old name.
dduugg
added a commit
to rubyatscale/pks
that referenced
this pull request
Sep 29, 2026
Replaces the copy of the zizmor workflow with a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32), so zizmor-action bumps and fixes land once in shared-config instead of in every repo. It keeps the default advanced-security: true, so results still upload to the Security tab and the same triggers apply. The job no longer requests actions: read, which upload-sarif only needs in private repos. The check is now named "zizmor / zizmor"; no ruleset requires the old name. .github/zizmor.yml still applies: zizmor finds it in the checked-out repo, as before.
dduugg
added a commit
to rubyatscale/rubyfmt-action
that referenced
this pull request
Sep 29, 2026
Replaces the copy of the zizmor workflow with a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32), so zizmor-action bumps and fixes land once in shared-config instead of in every repo. It keeps the default advanced-security: true, so results still upload to the Security tab and the same triggers apply. The job no longer requests actions: read, which upload-sarif only needs in private repos. The check is now named "zizmor / zizmor"; no ruleset requires the old name. This moves zizmor-action from v0.6.3 to v0.6.4, the version shared-config pins.
This was referenced Sep 29, 2026
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
zizmor.ymlbecomes aworkflow_callworkflow, so gem repos can call zizmor from here instead of each keeping its own copy. This follows what #29 did forcodeql.yml.zizmor-self-scan.ymlkeeps the push and PR triggers and calls$/.github/workflows/zizmor.yml, GitHub's self-repository syntax. shared-config still scans itself and uploads to the Security tab as before.$/resolves to the commit that is running, so a PR that editszizmor.ymlis tested against its own version.codeql-self-scan.ymlswitches from./to$/too: zizmor 1.30'sself-repositoryaudit flags./, and the v0.6.4 bump below would otherwise add that alert on main.advanced-securityinput (boolean, defaulttrue, zizmor-action's default):trueuploads the results to the Security tab, as the current workflow does.falsereports findings as annotations and fails the job.false, because zizmor exits 0 whenever it writes SARIF. I checked locally: zizmor 1.30.0 on a workflow with findings exits 0 with--format sarifand 14 with--format github.ci.ymlandcd.ymldo the same.zizmor / zizmorwith the example) and notes that callers tracking@mainpick up zizmor-action upgrades, and any new audits, at once.codeql.ymlorcodeql-self-scan.ymlto the README. Both are now in the tables, with a caller example and thelanguagesinput.action.shis the same in both versions.The first caller will be rubyatscale/singed, which will use
advanced-security: falseso zizmor can be a required check there.Test plan
$/calls, which actionlint 1.7.12 doesn't recognize yet (Support the new$/self-repositoryuses:syntax rhysd/actionlint#711).$/, and the zizmor scan uploads to code scanning. Theself-repositoryalerts (#44, #45) show as fixed.