Skip to content

ci: adjust zizmor advanced security handling#34

Merged
wochinge merged 1 commit into
mainfrom
codex/zizmor-fork-pr-blocks
May 21, 2026
Merged

ci: adjust zizmor advanced security handling#34
wochinge merged 1 commit into
mainfrom
codex/zizmor-fork-pr-blocks

Conversation

@wochinge
Copy link
Copy Markdown
Contributor

What changed

  • Run zizmor-action with advanced-security: false for non-push events, including pull requests and merge queue runs.
  • Keep Advanced Security/SARIF uploads enabled on push events.
  • Set min-severity: low for the zizmor scan.

Why

Fork pull requests cannot upload code scanning results to GitHub Advanced Security, so requiring zizmor code scanning results blocks community PRs. This keeps the check usable for fork PRs while preserving SARIF upload on trusted pushes.

Validation

  • YAML parse check for .github/workflows/zizmor.yml
  • git diff --check -- .github/workflows/zizmor.yml

@wochinge wochinge marked this pull request as ready for review May 21, 2026 09:03
@wochinge wochinge requested a review from a team as a code owner May 21, 2026 09:03
@wochinge wochinge merged commit d9d5361 into main May 21, 2026
5 checks passed
@wochinge wochinge deleted the codex/zizmor-fork-pr-blocks branch May 21, 2026 09:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant