Set actions/checkout to not persist credentials and improve workflow logic - #798
Conversation
Summary by CodeRabbit
WalkthroughThe pull request disables persisted Git credentials across GitHub Actions checkout steps. It also routes PlatformIO matrix environments through variables, makes Clang summaries fail on any failed check, and changes ESPHome matrix failure handling. ChangesWorkflow hardening
Merge Risk: 🔵 Low · up to The workflow matrix may stop validating the latest ESPHome version when another matrix job fails, reducing CI coverage. The PR is mergeable with owner awareness or follow-up to restore fail-fast: false. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.) ✨ Finishing Touches✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Team
Run ID: 83bc6e39-0dff-4dec-8717-758226c4d9cf
📒 Files selected for processing (15)
.github/workflows/biome.yml.github/workflows/clang.yml.github/workflows/dependabot.yml.github/workflows/end-of-life.yml.github/workflows/generate.yml.github/workflows/ikea-frekvens-led-multi-use-light.yml.github/workflows/ikea-frekvens-led-spotlight.yml.github/workflows/ikea-obegransad-led-wall-lamp.yml.github/workflows/labeler.yml.github/workflows/miscellaneous.yml.github/workflows/platformio.yml.github/workflows/ruff.yml.github/workflows/stream.yml.github/workflows/version.yml.github/workflows/wiki.yml
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.
📜 Review details
🧰 Additional context used
🪛 zizmor (1.29.0)
.github/workflows/generate.yml
[info] 58-58: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
[info] 137-137: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
[info] 200-200: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
🔇 Additional comments (22)
.github/workflows/biome.yml (2)
21-22: LGTM!
39-40: LGTM!.github/workflows/clang.yml (5)
23-24: LGTM!
43-44: LGTM!
96-97: LGTM!
113-114: LGTM!
223-223: LGTM!.github/workflows/dependabot.yml (1)
23-24: LGTM!.github/workflows/end-of-life.yml (1)
47-48: LGTM!.github/workflows/ruff.yml (2)
21-22: LGTM!
37-38: LGTM!.github/workflows/stream.yml (2)
28-29: LGTM!
106-107: LGTM!.github/workflows/version.yml (1)
29-30: LGTM!.github/workflows/wiki.yml (1)
26-27: LGTM!.github/workflows/generate.yml (1)
20-21: LGTM!Also applies to: 66-67, 137-137, 145-146, 200-200
.github/workflows/ikea-frekvens-led-multi-use-light.yml (1)
28-29: LGTM!Also applies to: 57-58, 79-80, 96-96, 110-111, 127-128, 153-153, 180-181, 202-203, 289-289, 316-317, 338-339, 457-457
.github/workflows/ikea-frekvens-led-spotlight.yml (1)
23-24: LGTM!Also applies to: 36-36, 45-46
.github/workflows/ikea-obegransad-led-wall-lamp.yml (1)
28-29: LGTM!Also applies to: 57-58, 79-80, 95-95, 109-110, 126-127, 152-152, 179-180, 201-202, 285-285, 312-313, 334-335, 452-452
.github/workflows/miscellaneous.yml (1)
20-21: LGTM!Also applies to: 121-122, 153-154, 186-187, 209-210
.github/workflows/labeler.yml (1)
22-23: LGTM!.github/workflows/platformio.yml (1)
21-22: LGTM!
| runs-on: ubuntu-latest | ||
| continue-on-error: true | ||
|
|
||
| strategy: | ||
| fail-fast: false |
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Team
Run ID: 7dd5723a-7513-47e0-83b4-d18f85a7eda1
📒 Files selected for processing (1)
.github/workflows/ikea-frekvens-led-spotlight.yml
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.
📜 Review details
⏰ Context from checks skipped due to timeout. (85)
- GitHub Check: Minimal (lolin_s3_mini)
- GitHub Check: Minimal (seeed_xiao_esp32c3)
- GitHub Check: Minimal (esp32-c5-devkitc-1)
- GitHub Check: Minimal (seeed_xiao_esp32s3)
- GitHub Check: Minimal (lolin_d32_pro)
- GitHub Check: Minimal (adafruit_qtpy_esp32s2)
- GitHub Check: Minimal (adafruit_qtpy_esp32s3_nopsram)
- GitHub Check: Minimal (esp32-s3-devkitc-1)
- GitHub Check: Default (lolin_d32)
- GitHub Check: Minimal (lolin_d32)
- GitHub Check: Default (esp32dev)
- GitHub Check: Default (seeed_xiao_esp32c6)
- GitHub Check: Minimal (seeed_xiao_esp32c6)
- GitHub Check: Default (lolin_s3_mini)
- GitHub Check: Minimal (wemos_d1_mini32)
- GitHub Check: Minimal (esp32-c6-devkitm-1)
- GitHub Check: Default (wemos_d1_mini32)
- GitHub Check: Minimal (adafruit_qtpy_esp32s3_n4r2)
- GitHub Check: Default (seeed_xiao_esp32s3)
- GitHub Check: Default (lolin_d32_pro)
- GitHub Check: Minimal (esp32-c3-devkitm-1)
- GitHub Check: Default (esp32-c6-devkitm-1)
- GitHub Check: Default (adafruit_qtpy_esp32s3_n4r2)
- GitHub Check: Default (esp32-c3-devkitm-1)
- GitHub Check: Default (esp32-c5-devkitc-1)
- GitHub Check: Default (esp32-s3-devkitc-1)
- GitHub Check: Default (adafruit_qtpy_esp32s3_nopsram)
- GitHub Check: Default (adafruit_qtpy_esp32s2)
- GitHub Check: Minimal (esp32dev)
- GitHub Check: Default (seeed_xiao_esp32c3)
- GitHub Check: Typical (seeed_xiao_esp32s3)
- GitHub Check: Extensive (seeed_xiao_esp32s3)
- GitHub Check: Typical (esp32-s3-devkitc-1)
- GitHub Check: Typical (adafruit_qtpy_esp32s3_nopsram)
- GitHub Check: Extensive (esp32-s3-devkitc-1)
- GitHub Check: Extensive (adafruit_qtpy_esp32s3_nopsram)
- GitHub Check: Minimal (lolin_d32)
- GitHub Check: Default (lolin_d32_pro)
- GitHub Check: Minimal (seeed_xiao_esp32c3)
- GitHub Check: Minimal (lolin_s3_mini)
- GitHub Check: Minimal (seeed_xiao_esp32c6)
- GitHub Check: Minimal (esp32-c3-devkitm-1)
- GitHub Check: Default (esp32-s3-devkitc-1)
- GitHub Check: Minimal (esp32dev)
- GitHub Check: Default (esp32-c6-devkitm-1)
- GitHub Check: Minimal (wemos_d1_mini32)
- GitHub Check: Minimal (lolin_d32_pro)
- GitHub Check: Minimal (seeed_xiao_esp32s3)
- GitHub Check: Default (seeed_xiao_esp32s3)
- GitHub Check: Default (seeed_xiao_esp32c3)
- GitHub Check: Default (seeed_xiao_esp32c6)
- GitHub Check: Default (lolin_s3_mini)
- GitHub Check: Minimal (esp32-s3-devkitc-1)
- GitHub Check: Default (esp32-c5-devkitc-1)
- GitHub Check: Minimal (esp32-c5-devkitc-1)
- GitHub Check: Default (wemos_d1_mini32)
- GitHub Check: Minimal (adafruit_qtpy_esp32s3_n4r2)
- GitHub Check: Minimal (esp32-c6-devkitm-1)
- GitHub Check: Default (adafruit_qtpy_esp32s3_n4r2)
- GitHub Check: Default (adafruit_qtpy_esp32s2)
- GitHub Check: Minimal (adafruit_qtpy_esp32s2)
- GitHub Check: Default (lolin_d32)
- GitHub Check: Default (adafruit_qtpy_esp32s3_nopsram)
- GitHub Check: Minimal (adafruit_qtpy_esp32s3_nopsram)
- GitHub Check: Default (esp32-c3-devkitm-1)
- GitHub Check: Default (esp32dev)
- GitHub Check: Extensive (seeed_xiao_esp32s3)
- GitHub Check: Typical (adafruit_qtpy_esp32s3_nopsram)
- GitHub Check: Extensive (adafruit_qtpy_esp32s3_nopsram)
- GitHub Check: Extensive (esp32-s3-devkitc-1)
- GitHub Check: Typical (seeed_xiao_esp32s3)
- GitHub Check: Typical (esp32-s3-devkitc-1)
- GitHub Check: Tidy (IKEA_FREKVENS, esp32-c6-devkitm-1)
- GitHub Check: Tidy (IKEA_OBEGRANSAD, esp32-c3-devkitm-1)
- GitHub Check: Tidy (IKEA_FREKVENS, esp32-c5-devkitc-1)
- GitHub Check: Tidy (IKEA_FREKVENS, esp32-c3-devkitm-1)
- GitHub Check: Tidy (IKEA_OBEGRANSAD, esp32dev)
- GitHub Check: Tidy (IKEA_OBEGRANSAD, esp32-c5-devkitc-1)
- GitHub Check: Tidy (IKEA_OBEGRANSAD, esp32-c6-devkitm-1)
- GitHub Check: Tidy (IKEA_OBEGRANSAD, esp32-s3-devkitc-1)
- GitHub Check: Tidy (IKEA_FREKVENS, esp32dev)
- GitHub Check: Tidy (IKEA_FREKVENS, esp32-s3-devkitc-1)
- GitHub Check: copilot-pull-request-reviewer
- GitHub Check: ESPHome (2025.7.0)
- GitHub Check: ESPHome (latest)
🔇 Additional comments (1)
.github/workflows/ikea-frekvens-led-spotlight.yml (1)
23-24: LGTM!Also applies to: 45-46
This pull request enhances the security of the CI workflows by disabling credential persistence during the checkout process and refactoring the workflow logic for clarity.
Key changes
persist-credentialsto false in theactions/checkoutstep across multiple workflows.Impact
These changes improve security by reducing the risk of credential leakage and enhance maintainability of the CI workflows. Users and contributors will benefit from clearer and more secure workflows without any breaking changes.