Skip to content

chore(zizmor): drop the local policy copy, the reusable supplies it - #640

Merged
CybotTM merged 1 commit into
mainfrom
chore/sync-zizmor-comment
Aug 2, 2026
Merged

chore(zizmor): drop the local policy copy, the reusable supplies it#640
CybotTM merged 1 commit into
mainfrom
chore/sync-zizmor-comment

Conversation

@CybotTM

@CybotTM CybotTM commented Aug 2, 2026

Copy link
Copy Markdown
Member

Removes .github/zizmor.yml. netresearch/.github#339 makes the zizmor reusable fetch the organisation policy at run time when a repo has no file of its own, and drops it from all five templates, so this copy no longer has a job.

It is not harmless to leave behind. A local file takes precedence over the fetched one, so this repository would keep running an old policy the next time the shared one actually changes — which is exactly how a two-line policy ended up needing a pull request in 54 repositories to reword a comment.

The scan result does not change: the same policy is applied, from one place instead of 54. A repository that genuinely needs a different policy opts out by keeping its own .github/zizmor.yml; this one was byte-identical to the template, which was verified before deleting.

This pull request previously carried the comment rewording from #336. That became pointless once the file itself moved, so the branch was rewritten to delete it instead.

Copilot AI review requested due to automatic review settings August 2, 2026 16:16
@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions github-actions Bot added the ci label Aug 2, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Updates the documentation comment in .github/zizmor.yml to accurately describe what the enforced ref-pin policy checks (ref vs SHA) versus what is only a team convention (using @main).

Changes:

  • Clarifies that zizmor enforces “ref-pinned vs SHA-pinned” rather than enforcing a specific ref like @main.
  • Updates wording to avoid implying zizmor can validate whether @main is used.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@codecov

codecov Bot commented Aug 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 70.89%. Comparing base (cbdccfa) to head (9092e5f).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #640   +/-   ##
=======================================
  Coverage   70.89%   70.89%           
=======================================
  Files          36       36           
  Lines        3567     3567           
=======================================
  Hits         2529     2529           
  Misses        876      876           
  Partials      162      162           
Flag Coverage Δ
e2e 58.99% <ø> (ø)
unittests 71.38% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

github-actions[bot]
github-actions Bot previously approved these changes Aug 2, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated approval for maintainer PR

All automated quality gates passed. See SECURITY_CONTROLS.md for compensating controls.

netresearch/.github#339 makes the zizmor reusable fetch the organisation policy
at run time when a repo has no .github/zizmor.yml of its own, and removes the
file from the templates. Keeping a copy here would silently win over the shared
policy the next time it really changes, which is how this file came to differ
across the fleet in the first place.

The scan itself is unchanged: the same policy is applied, from one place.

Signed-off-by: Sebastian Mendel <github@sebastianmendel.de>
@CybotTM
CybotTM force-pushed the chore/sync-zizmor-comment branch from 9d81552 to 9092e5f Compare August 2, 2026 17:51
@CybotTM CybotTM changed the title docs(zizmor): describe the rule that is actually enforced chore(zizmor): drop the local policy copy, the reusable supplies it Aug 2, 2026
@sonarqubecloud

sonarqubecloud Bot commented Aug 2, 2026

Copy link
Copy Markdown

@CybotTM
CybotTM requested a review from Copilot August 2, 2026 17:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated approval for maintainer PR

All automated quality gates passed. See SECURITY_CONTROLS.md for compensating controls.

@CybotTM
CybotTM added this pull request to the merge queue Aug 2, 2026
Merged via the queue into main with commit b39abd8 Aug 2, 2026
32 checks passed
@CybotTM
CybotTM deleted the chore/sync-zizmor-comment branch August 2, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants