Skip to content

Add Zizmor analysis GitHub action#482

Merged
pankajkoti merged 1 commit into
mainfrom
add-zizmor-action
Jul 18, 2025
Merged

Add Zizmor analysis GitHub action#482
pankajkoti merged 1 commit into
mainfrom
add-zizmor-action

Conversation

@pankajkoti

@pankajkoti pankajkoti commented Jul 16, 2025

Copy link
Copy Markdown
Contributor

Adds an automated security analysis workflow that runs the Zizmor scanner on every push to main and on all pull requests.

related: https://github.com/astronomer/oss-integrations-private/issues/156

Reference: https://docs.zizmor.sh/

@github-advanced-security

Copy link
Copy Markdown

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 93.75%. Comparing base (3f30692) to head (b53fc29).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #482   +/-   ##
=======================================
  Coverage   93.75%   93.75%           
=======================================
  Files          11       11           
  Lines        1040     1040           
=======================================
  Hits          975      975           
  Misses         65       65           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@pankajkoti
pankajkoti marked this pull request as ready for review July 16, 2025 13:35
@pankajkoti
pankajkoti requested a review from a team as a code owner July 16, 2025 13:35
@pankajastro

Copy link
Copy Markdown
Contributor

I'm just wondering if this job by default, uploads the scan artifact. I can see in the log Uploading combined SARIF debug artifact, but it is empty https://github.com/astronomer/dag-factory/actions/runs/16320884127/job/46098049719#step:5:3

Comment thread .github/workflows/zizmor.yml
@pankajkoti
pankajkoti merged commit b4f7d44 into main Jul 18, 2025
63 checks passed
@pankajkoti
pankajkoti deleted the add-zizmor-action branch July 18, 2025 14:10
@pankajastro pankajastro added this to the DAG Factory 1.0.0 milestone Jul 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants