Skip to content

chore: zizmor ruleset pilot branch (#326)#155

Open
isaiah-grafana wants to merge 3 commits intomainfrom
test/zizmor-vendor-excludes-326
Open

chore: zizmor ruleset pilot branch (#326)#155
isaiah-grafana wants to merge 3 commits intomainfrom
test/zizmor-vendor-excludes-326

Conversation

@isaiah-grafana
Copy link
Copy Markdown
Contributor

@isaiah-grafana isaiah-grafana commented Apr 21, 2026

Summary

Recreates test/zizmor-vendor-excludes-326 as a branch on grafana/security-github-actions (same-repo PR into main), not from a fork head.

self-zizmor.yaml matches main: uses: grafana/shared-workflows/.../reusable-zizmor.yml@5cec40b (no isaiah-grafana fork pin).

Closes the fork-based workflow from the prior PR; org rulesets should point at this repo + branch.

Ref: https://github.com/grafana/security-appsec/issues/326

Recreate test/zizmor-vendor-excludes-326 on grafana/security-github-actions with the same self-zizmor config as main (grafana/shared-workflows pin). Same-repo PR flow into main.
…ludes-326 (#326)

Point self-zizmor at isaiah-grafana/shared-workflows by branch ref so the
ruleset pilot picks up workflow changes without bumping SHAs.

Made-with: Cursor
@isaiah-grafana isaiah-grafana requested a review from a team as a code owner April 21, 2026 20:17
@isaiah-grafana isaiah-grafana force-pushed the test/zizmor-vendor-excludes-326 branch from e8b4e2a to d224d87 Compare April 21, 2026 20:18
Comment thread .github/workflows/self-zizmor.yaml Fixed
Updated the workflow to use the correct repository path for reusable-zizmor.yml.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants