Skip to content

Ignore zizmor self-repository audit in CI - #66

Merged
rblaine95 merged 1 commit into
masterfrom
ci/zizmor-self-repository
Sep 25, 2026
Merged

rblaine95 merged 1 commit into
masterfrom
ci/zizmor-self-repository

Conversation

@rblaine95

@rblaine95 rblaine95 commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Summary

zizmor 1.30.0 added the self-repository audit, which failed the lint job in run 36166326608. It flags the five uses: ./.github/workflows/*.yml calls in cargo.yml and wants GitHub's new uses: $/... syntax.

actionlint 1.7.12 doesn't accept $/ yet. It reports a workflow-call format error on every call, so switching syntax would just move the failure to a different hook.

Change

  • Add # zizmor: ignore[self-repository] to each reusable workflow call in .github/workflows/cargo.yml. This follows the existing ref-version-mismatch ignores.
  • Add a two-line comment above jobs: saying why.

Remove the ignores once actionlint accepts $/.

Testing

  • zizmor over all workflows: no findings (5 ignored).
  • actionlint .github/workflows/cargo.yml: passes.
  • I checked the $/ form against actionlint 1.7.12 on a scratch copy of the workflows. All five calls fail.

Summary by CodeRabbit

  • Chores
    • Updated continuous integration workflow checks to remain compatible with the current workflow validation tooling. No changes were made to workflow permissions, dependencies, or job behavior.

zizmor 1.30.0 added a `self-repository` audit that flags the five
workspace-relative `uses: ./.github/workflows/*.yml` calls in
`cargo.yml` and asks for GitHub's new `uses: $/...` syntax.

actionlint 1.7.12 rejects the `$/` form with a `workflow-call` format
error, so switching would trade one failing hook for another. Keep the
`./` form and add inline `zizmor: ignore[self-repository]` comments,
matching the existing `ref-version-mismatch` suppressions.

Drop the ignores once actionlint accepts `$/`.

Ave Deus Mechanicus
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: a65b82e1-e725-4f18-b0b5-b004a57cf172

📥 Commits

Reviewing files that changed from the base of the PR and between d0d0d4e and 83f83ac.

📒 Files selected for processing (1)
  • .github/workflows/cargo.yml
 _________________________________________________
< Code Wars Episode VI: Return of the Unit Tests. >
 -------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@rblaine95
rblaine95 merged commit afe0e62 into master Sep 25, 2026
6 of 7 checks passed
@rblaine95
rblaine95 deleted the ci/zizmor-self-repository branch September 25, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant