diff --git a/.github/workflows/auto-label-issues.yml b/.github/workflows/auto-label-issues.yml index 2e897310bcd..25024532146 100644 --- a/.github/workflows/auto-label-issues.yml +++ b/.github/workflows/auto-label-issues.yml @@ -10,7 +10,7 @@ jobs: steps: - name: Check if organization member id: is-org-member - uses: JamesSingleton/is-organization-member@39c59b3b17cca4eb75c81772b95e724e2a24c025 # v1.0.0 + uses: JamesSingleton/is-organization-member@39c59b3b17cca4eb75c81772b95e724e2a24c025 # 1.0.0 with: organization: ${{ github.repository_owner }} username: ${{ github.event.issue.user.login }} diff --git a/.github/workflows/braintrust-evals.yml b/.github/workflows/braintrust-evals.yml index d05093acd61..02c443fce54 100644 --- a/.github/workflows/braintrust-evals.yml +++ b/.github/workflows/braintrust-evals.yml @@ -11,7 +11,6 @@ concurrency: cancel-in-progress: true permissions: - pull-requests: write contents: read jobs: @@ -51,6 +50,8 @@ jobs: eval: name: Run evals needs: preflight + permissions: + pull-requests: write if: github.event_name == 'push' || (github.event_name == 'pull_request' && contains(github.event.pull_request.labels.*.name, 'run-evals') && github.event.pull_request.head.repo.full_name == github.repository) runs-on: ubuntu-latest timeout-minutes: 20 diff --git a/.github/workflows/docs-lint-v2.yml b/.github/workflows/docs-lint-v2.yml index 69c5c477436..96e14114471 100644 --- a/.github/workflows/docs-lint-v2.yml +++ b/.github/workflows/docs-lint-v2.yml @@ -47,7 +47,7 @@ jobs: - name: cache cargo id: cache-cargo if: steps.filter.outputs.docs == 'true' - uses: actions/cache@8b402f58fbc84540c8b491a91e594a4576fec3d7 # v5 + uses: actions/cache@8b402f58fbc84540c8b491a91e594a4576fec3d7 # v5.0.2 with: path: | ~/.cargo/bin/ diff --git a/.github/workflows/fix-typos.yml b/.github/workflows/fix-typos.yml index 6d4450e5749..ae2f45cf87d 100644 --- a/.github/workflows/fix-typos.yml +++ b/.github/workflows/fix-typos.yml @@ -20,7 +20,7 @@ jobs: with: persist-credentials: false ref: master - - uses: sobolevn/misspell-fixer-action@06ff0b508d4f4c0ba70d15f9a628232c0aade536 # v0.1.0 + - uses: sobolevn/misspell-fixer-action@06ff0b508d4f4c0ba70d15f9a628232c0aade536 # 0.1.0 - name: Generate token id: app-token diff --git a/.github/workflows/publish_image.yml b/.github/workflows/publish_image.yml index 9de76e62f1e..817541de8d3 100644 --- a/.github/workflows/publish_image.yml +++ b/.github/workflows/publish_image.yml @@ -8,8 +8,6 @@ on: permissions: contents: read - packages: write - id-token: write jobs: settings: @@ -145,6 +143,10 @@ jobs: needs: - settings - merge_manifest + permissions: + contents: read + packages: write + id-token: write # Call workflow explicitly because events from actions cannot trigger more actions uses: ./.github/workflows/mirror.yml with: diff --git a/.github/workflows/self-host-tests-smoke.yml b/.github/workflows/self-host-tests-smoke.yml index d09f06b80fa..983a182d52d 100644 --- a/.github/workflows/self-host-tests-smoke.yml +++ b/.github/workflows/self-host-tests-smoke.yml @@ -23,13 +23,13 @@ jobs: config: [default, logs, envoy, rustfs, envoy-rustfs] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 with: persist-credentials: false sparse-checkout: | docker/ - - uses: actions/setup-node@v4 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: '22' diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 00000000000..f6df8c9d8fd --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,58 @@ +name: zizmor + +on: + pull_request: + branches: + - 'master' + paths: + - '.github/workflows/**' + - 'zizmor.yml' + +# Cancel old builds on new commit for same workflow + branch/PR +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +env: + ZIZMOR_VERSION: 1.26.1 + +jobs: + zizmor: + name: zizmor + runs-on: blacksmith-4vcpu-ubuntu-2404 + steps: + - name: Checkout + uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 + with: + persist-credentials: false + sparse-checkout: | + .github/workflows + zizmor.yml + + - name: Cache zizmor binary + id: cache-zizmor + uses: actions/cache@8b402f58fbc84540c8b491a91e594a4576fec3d7 # v5.0.2 + with: + path: ~/.local/bin/zizmor + key: zizmor-${{ runner.os }}-${{ runner.arch }}-${{ env.ZIZMOR_VERSION }} + + - name: Download zizmor + if: steps.cache-zizmor.outputs.cache-hit != 'true' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + set -euo pipefail + archive="zizmor-x86_64-unknown-linux-gnu.tar.gz" + curl -sSLO "https://github.com/zizmorcore/zizmor/releases/download/v${ZIZMOR_VERSION}/${archive}" + gh attestation verify "${archive}" --repo zizmorcore/zizmor + mkdir -p ~/.local/bin + tar -xzf "${archive}" -C ~/.local/bin zizmor + chmod +x ~/.local/bin/zizmor + + - name: Run zizmor + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: ~/.local/bin/zizmor --config zizmor.yml .github/workflows diff --git a/zizmor.yml b/zizmor.yml new file mode 100644 index 00000000000..ae5824146ce --- /dev/null +++ b/zizmor.yml @@ -0,0 +1,8 @@ +rules: + dangerous-triggers: + ignore: + - "authorize-vercel-deploys.yml" + - "docs-lint-v2-comment.yml" + - "external-pr-comment.yml" + - "label_prs.yml" + - "studio-master-alert.yml"