Repository navigation
ci: lint workflows with actionlint and zizmor, and let Dependabot update npm - #12
Merged
Merged
Conversation
Jobs that never push no longer leave the job token in .git/config, where any later step or uploaded artefact could read it. The release job's checkout already opted out and is unchanged. The Required Checks job printed toJSON(needs) inside a single-quoted echo, so a quote in any job output would end the string and run as shell. It now reaches the script through env.
Nothing stopped a tag-pinned third-party action, an unknown runner label or a script injection from coming back into the workflows. Actionlint (with shellcheck) and zizmor now run as their own jobs on the runner determine-runner selects, and Required Checks waits on both. Both tools are pinned: actionlint and shellcheck by version and SHA-256 per runner architecture, zizmor through uvx at an exact version, offline. .github/actionlint.yaml lists the fleet and Blacksmith runner labels. .github/zizmor.yml requires a commit SHA for every action outside ExaDev and disables self-repository, whose `$/` syntax actionlint rejects. adhoc-packages is ignored inline on the release job's pinned npm upgrade and on the package job's tarball install, which moves to a step of its own because zizmor reads ignore comments only as YAML comments, not inside a multi-line script.
The npm entry mirrors the github-actions one: weekly, minor and patch updates grouped, and a seven-day cooldown matching the minimum release age local installs enforce.
Mearman
marked this pull request as ready for review
October 3, 2026 13:09
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
🎉 This PR is included in version 1.1.5 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds Actionlint and Zizmor jobs to CI, copied from monorepo-template: actionlint 1.7.12 and shellcheck 0.11.0 downloaded at pinned versions and checked against SHA-256 digests per runner architecture, and zizmor 1.30.1 through
uvx, offline. Both run on the runner determine-runner selects and are joined into Required Checks, so the required check name is unchanged..github/actionlint.yamllistsexadev-runnersand the Blacksmith label determine-runner runs on and falls back to;.github/zizmor.ymlrequires a commit SHA for every action outside ExaDev (ExaDev/*may use a tag) and disablesself-repository, whose$/syntax actionlint still rejects (rhysd/actionlint#711).Findings on the existing workflow, before this change:
artipackedon the commitlint, lint, typecheck, mutation and package checkouts: fixed withpersist-credentials: false. None of them pushes; the release job's checkout already had it and is untouched.template-injectiononecho '${{ toJSON(needs) }}'in Required Checks: the JSON now arrives throughenv.adhoc-packageson the release job'snpm install -g npm@11.20.0and on the package job'snpm installof the packed tarball withcosmiconfig@<major>: ignored inline on each line. The first is an exact, deliberately chosen pin and the release job's behaviour is unchanged; the second is the lockfile-free consumer install the job exists to test. zizmor only reads an ignore comment as a YAML comment, not inside a multi-linerun:script, so that install moves into a step of its own with the same command and working directory.With the configs from this branch, both commands as CI runs them fail on a deliberately bad workflow in a scratch repository (tag-pinned
actions/checkout@v4, unknown runner label,${{ github.event.pull_request.title }}inrun:, an unquoted variable): actionlint exits 1 (runner-label, expression, shellcheck SC2086) and zizmor exits 14 (unpinned-uses, template-injection, artipacked, excessive-permissions).Dependabot also gets an npm entry with the same weekly schedule, grouped minor and patch updates and the same
cooldown: default-days: 7as the github-actions entry, matching the seven-day minimum release age local installs use. Thecooldownkeys are checked against GitHub's Dependabot options reference (https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference, archived at https://web.archive.org/web/20261001095248/https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference):default-daysandexcludeare supported for npm, and cooldown never delays security updates.