Skip to content

Feat/zizmor grafana bench#115

Merged
isaiah-grafana merged 2 commits intomainfrom
feat/zizmor-grafana-bench
Mar 12, 2026
Merged

Feat/zizmor grafana bench#115
isaiah-grafana merged 2 commits intomainfrom
feat/zizmor-grafana-bench

Conversation

@isaiah-grafana
Copy link
Copy Markdown
Contributor

@isaiah-grafana isaiah-grafana commented Mar 9, 2026

Summary

Points Zizmor at the shared-workflows reusable workflow (with Grafana Bench Prometheus metrics) and cleans up TruffleHog/bench wiring so only Zizmor sends metrics for now.

Changes

  • self-zizmor.yaml: Call reusable workflow at grafana/shared-workflows/.github/workflows/reusable-zizmor.yml@feat/zizmor-grafana-bench so service/suite name come from the caller repo (fixes service=securityservice=grafana-security-github-actions).
  • reusable-trufflehog.yml: send-bench-metrics default set to false; Prometheus metrics from TruffleHog are disabled for now (only Zizmor sends to Prometheus).
  • TruffleHog: Example workflow uses dynamic service name (format('grafana-{0}', github.event.repository.name)) instead of hardcoded --service security; add TruffleHog grafana-bench example and docs as needed.
  • grafana-bench-stack: Removed; Zizmor metrics go through CI (reusable workflow + Vault) only.

Dependencies

  • Depends on shared-workflows feat/zizmor-grafana-bench (or @main after that PR is merged). Reusable workflow provides Vault-backed Prometheus and correct caller repo naming.

…rufflehog tweaks

- self-zizmor: call reusable-zizmor.yml@feat/zizmor-grafana-bench (correct service/suite name)
- TruffleHog: send-bench-metrics default false; example workflow uses dynamic service name
- Remove grafana-bench-stack (metrics via CI only); other trufflehog docs/example additions

Made-with: Cursor
@isaiah-grafana isaiah-grafana force-pushed the feat/zizmor-grafana-bench branch from ffd47d2 to 35b87da Compare March 12, 2026 20:34
@isaiah-grafana isaiah-grafana marked this pull request as ready for review March 12, 2026 20:42
@isaiah-grafana isaiah-grafana requested a review from a team as a code owner March 12, 2026 20:42
@isaiah-grafana isaiah-grafana merged commit 65eeb7c into main Mar 12, 2026
4 checks passed
@isaiah-grafana isaiah-grafana deleted the feat/zizmor-grafana-bench branch March 12, 2026 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant