Files
supabase/.github/workflows/zizmor.yml
Charis da724eb8c6 ci: add zizmor lint and harden GitHub Actions workflows (#47895)
## Summary
- Add a zizmor config and CI job that lints `.github/workflows` on every
PR touching it, downloading and attestation-verifying the pinned v1.26.1
release binary (cached across runs)
- Fix the mutable-tag and excess-permission findings zizmor surfaces in
`braintrust-evals.yml`, `publish_image.yml`, and
`self-host-tests-smoke.yml`: pin `actions/checkout`/`actions/setup-node`
to commit SHAs, and scope `pull-requests`/`packages`/`id-token`
permissions down to the specific jobs that need them

## Test plan
- [x] Confirm the `zizmor` job runs and passes on this PR

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added automated security scanning for workflow changes on pull
requests.
  * Added configuration to allow specific workflow trigger exceptions.

* **Security**
* Tightened GitHub Actions permissions at the workflow level and
re-granted only where required per job.
* Pinned common build action versions to specific commits for more
consistent execution.

* **Maintenance**
* Updated workflow caching and action step annotations without changing
linting or fixing behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-13 16:57:44 -04:00

59 lines
1.7 KiB
YAML

name: zizmor
on:
pull_request:
branches:
- 'master'
paths:
- '.github/workflows/**'
- 'zizmor.yml'
# Cancel old builds on new commit for same workflow + branch/PR
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
env:
ZIZMOR_VERSION: 1.26.1
jobs:
zizmor:
name: zizmor
runs-on: blacksmith-4vcpu-ubuntu-2404
steps:
- name: Checkout
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
with:
persist-credentials: false
sparse-checkout: |
.github/workflows
zizmor.yml
- name: Cache zizmor binary
id: cache-zizmor
uses: actions/cache@8b402f58fbc84540c8b491a91e594a4576fec3d7 # v5.0.2
with:
path: ~/.local/bin/zizmor
key: zizmor-${{ runner.os }}-${{ runner.arch }}-${{ env.ZIZMOR_VERSION }}
- name: Download zizmor
if: steps.cache-zizmor.outputs.cache-hit != 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
set -euo pipefail
archive="zizmor-x86_64-unknown-linux-gnu.tar.gz"
curl -sSLO "https://github.com/zizmorcore/zizmor/releases/download/v${ZIZMOR_VERSION}/${archive}"
gh attestation verify "${archive}" --repo zizmorcore/zizmor
mkdir -p ~/.local/bin
tar -xzf "${archive}" -C ~/.local/bin zizmor
chmod +x ~/.local/bin/zizmor
- name: Run zizmor
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: ~/.local/bin/zizmor --config zizmor.yml .github/workflows