Skip to content

chore: add zizmor and cleanup warnings - #4

Open
gforsyth wants to merge 6 commits into
rapidsfrom
zizmor
Open

chore: add zizmor and cleanup warnings#4
gforsyth wants to merge 6 commits into
rapidsfrom
zizmor

Conversation

@gforsyth

@gforsyth gforsyth commented Jun 23, 2026

Copy link
Copy Markdown

Part of rapidsai/build-planning#275

Adds zizmor checks to CI.

To try to avoid conflicts when updating from upstream, I tried to only touch the CI files that are run by us, so ci.yml and integration-tests.yml (and the actions they make use of).

Other workflow files are ignored in the zizmor.yml

I also pushed up this branch directly to the rapidsai fork to make sure that all of the explicit action pins were in the enterprise allowlist, and they run without issue

@jameslamb jameslamb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@trxcllnt @gforsyth could we merge this?

This would resolve the last thing needed to close rapidsai/build-planning#275.

And by the way I've also proposed similar changes upstream at mozilla#2760

@trxcllnt

Copy link
Copy Markdown
Collaborator

Can we just disable zizmor for this repo? I'd rather not deal with all the conflicts when merging in changes from upstream sccache.

@jameslamb

jameslamb commented Jul 22, 2026

Copy link
Copy Markdown
Member

IMO if we're going to have GitHub Actions running here, we should make these changes.

It's good that this appears not to use any of our self-hosted runners, but otherwise this repo's GitHub Actions workflows have a similar security posture to any of our other public repos.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants