Skip to content

ci(zizmor): Online-Audits zurueck, nur impostor-commit deaktiviert - #36

Merged
marcohost33-maker merged 1 commit into
mainfrom
claude/zizmor-praezisierung
Jun 6, 2026
Merged

marcohost33-maker merged 1 commit into
mainfrom
claude/zizmor-praezisierung

Conversation

@marcohost33-maker

Copy link
Copy Markdown
Owner

Summary

Selbst-Falsifikation aus der Meta-Auswertung 06-06: online-audits: false (PR#34) war zu grob. Praezise Loesung per docs.zizmor.sh/configuration: .github/zizmor.yml mit rules.impostor-commit.disable: true — nur das am privaten coworkerz-ci-Pin crashende Audit ist aus, known-vulnerable-actions + stale-action-refs wieder AKTIV.

Test plan

  • zizmor v1.25.2 lokal mit Config: "No findings", Exit 0
  • zizmor-Check gruen auf diesem PR (= Beweis mit repo-scoped CI-Token)

… aus

Praezisierung des Vormittags-Fixes (PR#34): Webrecherche ergab
rules.impostor-commit.disable in .github/zizmor.yml (zizmor >= v1.13) -
das deaktiviert NUR das crashende Audit; known-vulnerable-actions +
stale-action-refs bleiben online aktiv. Lokal: zizmor v1.25.2 mit Config
Exit 0. Echter Beweis = CI-Run mit repo-scoped Token auf diesem PR.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@marcohost33-maker marcohost33-maker added the agent:claude PR authored by Claude Code label Jun 6, 2026
@marcohost33-maker
marcohost33-maker marked this pull request as ready for review June 6, 2026 09:13
@marcohost33-maker
marcohost33-maker merged commit 3b94da9 into main Jun 6, 2026
16 checks passed
@marcohost33-maker
marcohost33-maker deleted the claude/zizmor-praezisierung branch June 6, 2026 09:13

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3433051ef8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/zizmor.yml
Comment on lines +8 to +10
rules:
impostor-commit:
disable: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Audit changes to the new zizmor configuration

When a future PR changes only this configuration—for example, disabling another security rule—the zizmor workflow will not run because both path filters in .github/workflows/zizmor.yml include only .github/workflows/** and .github/dependabot.yml. Since this file now directly controls which audits execute, add .github/zizmor.yml to the push and pull-request path filters so configuration-only changes are validated.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent:claude PR authored by Claude Code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant