Skip to content

Commit 66f2a53

Browse files
test: pin zizmor reusable to fork SHA for vendor path excludes (#326)
Point self-zizmor at isaiah-grafana/shared-workflows@242628b for ruleset testing of .github/zizmor-collection-ignore. Revert to grafana/shared-workflows after upstream merge. Made-with: Cursor
1 parent c99180c commit 66f2a53

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

.github/workflows/self-zizmor.yaml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,9 @@ jobs:
4545
- zizmor-check
4646
if: ${{ needs.zizmor-check.outputs.found-files == 'true' }}
4747

48-
uses: grafana/shared-workflows/.github/workflows/reusable-zizmor.yml@e7a3275d4c4978a3514801ec55708f1c599a6906
48+
# Testing security-appsec#326: reusable with optional .github/zizmor-collection-ignore. Point org rulesets at
49+
# branch test/zizmor-vendor-excludes-326 to validate; replace with grafana/shared-workflows@<merge SHA> for main.
50+
uses: isaiah-grafana/shared-workflows/.github/workflows/reusable-zizmor.yml@242628b1464cb1ecfb92b208f2bb8aaae795ec63
4951
with:
5052
runs-on: ${{ !github.event.repository.private && 'ubuntu-latest' || 'ubuntu-arm64-small' }}
5153
fail-severity: high

0 commit comments

Comments
 (0)