mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 19:05:06 +03:00
## Summary - Add a zizmor config and CI job that lints `.github/workflows` on every PR touching it, downloading and attestation-verifying the pinned v1.26.1 release binary (cached across runs) - Fix the mutable-tag and excess-permission findings zizmor surfaces in `braintrust-evals.yml`, `publish_image.yml`, and `self-host-tests-smoke.yml`: pin `actions/checkout`/`actions/setup-node` to commit SHAs, and scope `pull-requests`/`packages`/`id-token` permissions down to the specific jobs that need them ## Test plan - [x] Confirm the `zizmor` job runs and passes on this PR <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added automated security scanning for workflow changes on pull requests. * Added configuration to allow specific workflow trigger exceptions. * **Security** * Tightened GitHub Actions permissions at the workflow level and re-granted only where required per job. * Pinned common build action versions to specific commits for more consistent execution. * **Maintenance** * Updated workflow caching and action step annotations without changing linting or fixing behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
59 lines
1.7 KiB
YAML
59 lines
1.7 KiB
YAML
name: zizmor
|
|
|
|
on:
|
|
pull_request:
|
|
branches:
|
|
- 'master'
|
|
paths:
|
|
- '.github/workflows/**'
|
|
- 'zizmor.yml'
|
|
|
|
# Cancel old builds on new commit for same workflow + branch/PR
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
env:
|
|
ZIZMOR_VERSION: 1.26.1
|
|
|
|
jobs:
|
|
zizmor:
|
|
name: zizmor
|
|
runs-on: blacksmith-4vcpu-ubuntu-2404
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
|
|
with:
|
|
persist-credentials: false
|
|
sparse-checkout: |
|
|
.github/workflows
|
|
zizmor.yml
|
|
|
|
- name: Cache zizmor binary
|
|
id: cache-zizmor
|
|
uses: actions/cache@8b402f58fbc84540c8b491a91e594a4576fec3d7 # v5.0.2
|
|
with:
|
|
path: ~/.local/bin/zizmor
|
|
key: zizmor-${{ runner.os }}-${{ runner.arch }}-${{ env.ZIZMOR_VERSION }}
|
|
|
|
- name: Download zizmor
|
|
if: steps.cache-zizmor.outputs.cache-hit != 'true'
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
archive="zizmor-x86_64-unknown-linux-gnu.tar.gz"
|
|
curl -sSLO "https://github.com/zizmorcore/zizmor/releases/download/v${ZIZMOR_VERSION}/${archive}"
|
|
gh attestation verify "${archive}" --repo zizmorcore/zizmor
|
|
mkdir -p ~/.local/bin
|
|
tar -xzf "${archive}" -C ~/.local/bin zizmor
|
|
chmod +x ~/.local/bin/zizmor
|
|
|
|
- name: Run zizmor
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: ~/.local/bin/zizmor --config zizmor.yml .github/workflows
|