name: Workflow Lint # Lints .github/workflows/** for both: # - actionlint: YAML syntax, expression typing, shellcheck inside `run:` # blocks, unknown contexts, deprecated runner labels. # - zizmor: security misconfigurations — unpinned actions, dangerous # `${{ }}` interpolation, missing per-job permissions, etc. # # Scoped to PRs that touch .github/** only — keeps off the typical PR # critical path. on: pull_request: branches: [main] paths: - '.github/**' permissions: contents: read concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: actionlint: name: actionlint runs-on: ubuntu-latest timeout-minutes: 5 permissions: contents: read steps: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: persist-credentials: false # Pinned to v2.1.2. Verify SHA via: # gh api repos/raven-actions/actionlint/git/refs/tags/v2.1.2 # The action wraps the upstream `rhysd/actionlint` binary and emits # GitHub-annotation-formatted findings on PRs. - name: Run actionlint uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0 with: fail-on-error: true zizmor: runs-on: ubuntu-latest timeout-minutes: 10 permissions: contents: read security-events: write steps: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: persist-credentials: false - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.12' - name: Install zizmor # Pinned — resolves to whatever's latest on PyPI otherwise. # Bump via Dependabot pip ecosystem (see .github/dependabot.yml). run: pipx install zizmor==1.24.1 # Initial threshold: medium. High+ findings fail the job; medium findings # appear in the Security tab without blocking. Tune after first run. # Per-rule exemptions for pre-existing intentional patterns live in # .github/zizmor.yml (each carries a documented mitigation). - name: Run zizmor run: zizmor --config .github/zizmor.yml --format sarif --min-severity medium . > zizmor.sarif continue-on-error: true - name: Upload SARIF uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: sarif_file: zizmor.sarif category: zizmor - name: Fail on high+ findings run: zizmor --config .github/zizmor.yml --min-severity high .