# zizmor config — pre-existing intentional patterns flagged on initial introduction. # Each ignore below has a documented mitigation. Re-evaluate when the source workflow changes. # # To run zizmor locally with this config: # zizmor --config .github/zizmor.yml . rules: dangerous-triggers: ignore: # workflow_run is REQUIRED to post sticky comments on fork PRs — the # default-branch privileged token isn't accessible from `pull_request` # on a fork. Mitigated by: read-only `actions:read` + `contents:read` # for artifact download; `pull-requests:write` is the only write scope; # no checkout of fork code occurs. Header comment in the file documents. - ci-report.yml # workflow_run is the trusted half of the autofix pipeline. The # untrusted half (pr-autofix.yml) runs fork code with permissions:{} # and produces only a diff artifact (data, not executable code). The # publish job consumes the artifact, allowlist-validates every field # of metadata.json, then cross-checks identity against # workflow_run.head_sha / head_repository / head_branch via # pulls?head=owner:branch (commits/{sha}/pulls is empty for fork SHAs). # It never checks out fork code and never executes anything # fork-controlled. Header comment in the file documents the split. - pr-autofix-publish.yml # workflow_run is the trusted half of the vendored-grammar prebuild # pipeline (commit-fork-prebuilds.yml). The untrusted producer # (build-tree-sitter-prebuilds.yml on a fork pull_request) builds + # validates the .node prebuilds and uploads them as artifacts. This # consumer downloads ONLY those artifacts + metadata.json, # allowlist-validates every metadata field, cross-checks identity against # workflow_run.head_sha / head_repository / head_branch via # pulls?head=owner:branch (commits/{sha}/pulls is empty for fork SHAs), and # checks out the fork head pinned to that HEAD SHA solely to ADD prebuild # files (never executes fork code) before pushing. Header comment in the # file documents the split. - commit-fork-prebuilds.yml # pull_request_target needed by claude-code-action to access secrets # and post review comments on fork PRs. Mitigated by: PR checkouts pin # the fork's HEAD SHA (not the branch ref) to prevent TOCTOU races, # and claude-code-action sandboxes execution. Header comment documents. - claude.yml # pull_request_target on the autolabel job needs `pull-requests:write` # to apply labels. Mitigated by: release-drafter runs with `dry-run: # true`, reads only `.github/release-drafter.yml` from the BASE ref, # and the validate-title job (which runs untrusted `pull_request` # context) holds no write permissions. Header comment documents. - pr-labeler.yml # Note: cache-poisoning is NOT exempted. The two prior findings in # publish.yml and the former release-candidate.yml were fixed structurally # by dropping `cache: npm` from those workflows (matches the pattern used # by PyO3/maturin for the same audit). After the publish-workflow # unification (issue #1609), only publish.yml remains; the same # cache-poisoning hardening applies there.