chore(zizmor): drop the local policy copy, the reusable supplies it - #783
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #783 +/- ##
=======================================
Coverage 89.28% 89.28%
=======================================
Files 88 88
Lines 12147 12147
=======================================
Hits 10846 10846
Misses 1001 1001
Partials 300 300
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |
There was a problem hiding this comment.
Pull request overview
Updates the documentation comments in the zizmor configuration to accurately describe what the unpinned-uses rule enforces (ref-pinned vs SHA-pinned), while clearly separating tooling guarantees from human convention.
Changes:
- Clarifies that first-party
uses:entries are allowed to be pinned to a ref (branch/tag), not necessarily a full commit SHA. - Explicitly states that the specific ref choice (commonly
@main) is a convention enforced by review, not by zizmor.
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
There was a problem hiding this comment.
Automated approval for maintainer PR
All automated quality gates passed. See SECURITY_CONTROLS.md for compensating controls.
netresearch/.github#339 makes the zizmor reusable fetch the organisation policy at run time when a repo has no .github/zizmor.yml of its own, and removes the file from the templates. Keeping a copy here would silently win over the shared policy the next time it really changes, which is how this file came to differ across the fleet in the first place. The scan itself is unchanged: the same policy is applied, from one place. Signed-off-by: Sebastian Mendel <github@sebastianmendel.de>
d889c42 to
e0c6cc0
Compare
|
There was a problem hiding this comment.
Automated approval for maintainer PR
All automated quality gates passed. See SECURITY_CONTROLS.md for compensating controls.
…#340) GitHub deletes the `gh-readonly-queue` ref the moment a merge queue finishes, which races the SARIF upload inside `codeql-action/analyze`. `scorecard.yml` already guards against this and its comment calls the result "a guaranteed `ref ... not found` failure"; `zizmor.yml` skips its whole job for the same reason. `codeql.yml` never got the guard. The consequence is not a cosmetic red check: the queue run fails, and `github-merge-queue[bot]` **ejects the pull request from the queue**. It happened on [netresearch/ofelia#783](netresearch/ofelia#783), a pull request that deletes one YAML file and touches no Go code at all — added to the queue at 18:40:42, removed at 18:46:13, with `codeql / Analyze (go)` reporting `ref 'refs/heads/gh-readonly-queue/main/pr-783-...' not found in this repository`. Every merge-queue repository that calls this reusable is exposed to the same race. No analysis coverage is lost. The pull-request head is analysed before it ever reaches the queue, and the `push` and `schedule` events that keep the default-branch results current run against stable refs — which is exactly the reasoning already written down in `scorecard.yml`.



Removes
.github/zizmor.yml. netresearch/.github#339 makes the zizmor reusable fetch the organisation policy at run time when a repo has no file of its own, and drops it from all five templates, so this copy no longer has a job.It is not harmless to leave behind. A local file takes precedence over the fetched one, so this repository would keep running an old policy the next time the shared one actually changes — which is exactly how a two-line policy ended up needing a pull request in 54 repositories to reword a comment.
The scan result does not change: the same policy is applied, from one place instead of 54. A repository that genuinely needs a different policy opts out by keeping its own
.github/zizmor.yml; this one was byte-identical to the template, which was verified before deleting.This pull request previously carried the comment rewording from #336. That became pointless once the file itself moved, so the branch was rewritten to delete it instead.