Skip to content

ci: adds zizmor action - #144

Open
bmuenzenmeyer wants to merge 2 commits into
mainfrom
zizmor
Open

bmuenzenmeyer wants to merge 2 commits into
mainfrom
zizmor

Conversation

@bmuenzenmeyer

Copy link
Copy Markdown
Contributor

Same as doc-kit

Copilot AI lite review requested due to automatic review settings September 23, 2026 02:29
@bmuenzenmeyer
bmuenzenmeyer requested a review from a team as a code owner September 23, 2026 02:29
@vercel

vercel Bot commented Sep 23, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nodejs-learn Ready Ready Preview Sep 23, 2026 12:08pm UTC

Request Review

@github-actions

Copy link
Copy Markdown

👋 Codeowner Review Request

The following codeowners have been identified for the changed files:

Team reviewers: @nodejs/web-infra

Please review the changes when you have a chance. Thank you! 🙏

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Fix the invalid branch filter and prevent fork pull request SARIF uploads from failing.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds a GitHub Actions workflow to scan repository workflows with zizmor.

Changes:

  • Runs on pushes and pull requests targeting main.
  • Uses pinned actions and restricted permissions.
  • Uploads SARIF results to GitHub Advanced Security.
File Review findings
.github/​workflows/​zizmor.yml Critical: branches must use list syntax; the current scalar form invalidates the workflow. Moderate: Advanced Security uploads can fail for fork pull requests due to restricted token permissions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/zizmor.yml Outdated
Comment thread .github/workflows/zizmor.yml Outdated
Co-authored-by: Matt Cowley <me@mattcowley.co.uk>
Signed-off-by: Claudio Wunder <cwunder@gnome.org>

This branch was successfully deployed

1 active deployment
Preview 22983775 Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants