Skip to content

test: zizmor reusable fork pin for vendor excludes (#326)#146

Closed
isaiah-grafana wants to merge 4 commits intografana:mainfrom
isaiah-grafana:test/zizmor-vendor-excludes-326
Closed

test: zizmor reusable fork pin for vendor excludes (#326)#146
isaiah-grafana wants to merge 4 commits intografana:mainfrom
isaiah-grafana:test/zizmor-vendor-excludes-326

Conversation

@isaiah-grafana
Copy link
Copy Markdown
Contributor

@isaiah-grafana isaiah-grafana commented Apr 9, 2026

I used this branch to test rulesets against the #326 zizmor change: self-zizmor temporarily uses: isaiah-grafana/shared-workflows @ 242628b… so we could point rulesets at test/zizmor-vendor-excludes-326 on this repo.

Don’t merge this to main. Real rollout: merge grafana/shared-workflows#1861, then swap the uses: line to grafana/shared-workflows/... @ merge SHA here, put rulesets back to main, and close this.

https://github.com/grafana/security-appsec/issues/326

Point self-zizmor at isaiah-grafana/shared-workflows@242628b for ruleset
testing of .github/zizmor-collection-ignore. Revert to grafana/shared-workflows
after upstream merge.

Made-with: Cursor
@isaiah-grafana isaiah-grafana requested a review from a team as a code owner April 9, 2026 23:32
isaiah-grafana and others added 3 commits April 21, 2026 11:53
Point reusable-zizmor at isaiah-grafana/shared-workflows feat/zizmor-vendor-excludes-326
so org ruleset testing tracks latest fork pushes without bumping SHAs.
Resolve self-zizmor conflict: keep isaiah-grafana fork branch pin for #326.
Relax fail-severity to critical on this pilot branch so high-severity zizmor
findings do not block ruleset testing; restore high when pinning to upstream.
Code scanning flagged unpinned reusable workflow (branch ref). Pin
isaiah-grafana/shared-workflows reusable to commit ca9579cb3a5b072b4f75af091380536c01131610.
Comment thread .github/workflows/self-zizmor.yaml Fixed
@isaiah-grafana
Copy link
Copy Markdown
Contributor Author

Closing fork-head PR. Replacing with same-repo branch PR: test/zizmor-vendor-excludes-326 on grafana/security-github-actions into main (no isaiah-grafana fork head).

@isaiah-grafana isaiah-grafana deleted the test/zizmor-vendor-excludes-326 branch April 21, 2026 20:13
isaiah-grafana added a commit that referenced this pull request Apr 21, 2026
Re-apply reusable workflow pin to isaiah-grafana/shared-workflows@ca9579c
and fail-severity critical for ruleset pilot testing (same as pre-close branch).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants