mirror of
https://github.com/ArduPilot/ardupilot.git
synced 2026-10-02 10:23:25 +08:00
.github: add zizmor CI check
Scans .github/ for template injection, over-broad permissions, and unpinned actions/images on the same triggers as actionlint. The whole directory, not just the workflows: the composite actions under .github/actions/ carry run: blocks of their own and already trigger this job, but nothing in CI audits them -- actionlint does not shellcheck composite-action scripts. A template injection planted in save-ccache is not reported when only .github/workflows/ is scanned, and is a high finding when .github/ is. Annotate the ardupilot-dev-ros:latest image in colcon.yml and test_dds.yml: those jobs continuously test against the dev image itself, so they need to track "latest" rather than a pinned snapshot of it, and zizmor's unpinned-image check would otherwise flag that as unintentional. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
committed by
Peter Barker
co-authored by
Claude Opus 5
parent
d5420ff97c
commit
dd4e685f5a
@@ -1,5 +1,5 @@
|
||||
# actionlint configuration -- https://github.com/rhysd/actionlint
|
||||
# see .github/workflows/test_workflow_lint.yml for how CI invokes it
|
||||
# see .github/workflows/workflows_lint.yml for how CI invokes it
|
||||
|
||||
self-hosted-runner:
|
||||
# runners actionlint cannot know about; keep in sync with the runs-on: values
|
||||
|
||||
@@ -153,7 +153,10 @@ jobs:
|
||||
runs-on: ubuntu-22.04
|
||||
timeout-minutes: 60
|
||||
container:
|
||||
image: ardupilot/ardupilot-dev-ros:latest
|
||||
# deliberately floating: this is the continuous-testing job for the
|
||||
# ardupilot-dev-ros image itself, so it must track whatever "latest"
|
||||
# points at, not a pinned snapshot of it
|
||||
image: ardupilot/ardupilot-dev-ros:latest # zizmor: ignore[unpinned-images]
|
||||
steps:
|
||||
# Sparse checkout to make .github/actions/* available without polluting the colcon workspace
|
||||
- uses: actions/checkout@v7
|
||||
|
||||
@@ -154,7 +154,10 @@ jobs:
|
||||
actions: write # save-ccache prunes the previous cache entry
|
||||
runs-on: ubuntu-22.04
|
||||
container:
|
||||
image: ardupilot/ardupilot-dev-ros:latest
|
||||
# deliberately floating: this is the continuous-testing job for the
|
||||
# ardupilot-dev-ros image itself, so it must track whatever "latest"
|
||||
# points at, not a pinned snapshot of it
|
||||
image: ardupilot/ardupilot-dev-ros:latest # zizmor: ignore[unpinned-images]
|
||||
options: --user 1001
|
||||
strategy:
|
||||
fail-fast: false # don't cancel if a job from the matrix fails
|
||||
|
||||
@@ -7,12 +7,14 @@ on:
|
||||
- '.github/workflows/**'
|
||||
- '.github/actions/**'
|
||||
- '.github/actionlint.yaml'
|
||||
- '.github/zizmor.yml'
|
||||
|
||||
pull_request:
|
||||
paths:
|
||||
- '.github/workflows/**'
|
||||
- '.github/actions/**'
|
||||
- '.github/actionlint.yaml'
|
||||
- '.github/zizmor.yml'
|
||||
|
||||
workflow_dispatch:
|
||||
|
||||
@@ -47,3 +49,20 @@ jobs:
|
||||
shell: bash
|
||||
env:
|
||||
SHELLCHECK_OPTS: -e SC2086
|
||||
|
||||
- name: Install zizmor
|
||||
run: pip install zizmor==1.30.0
|
||||
|
||||
# workflow security: template injection, over-broad permissions,
|
||||
# unpinned actions and images; see .github/zizmor.yml.
|
||||
#
|
||||
# the whole of .github/, not just the workflows: composite actions under
|
||||
# .github/actions/ carry run: blocks of their own, which nothing else in
|
||||
# CI audits -- actionlint does not shellcheck them -- and dependabot.yml
|
||||
# is checked too.
|
||||
#
|
||||
# medium and above for now. The repo has no medium findings left, so
|
||||
# this gates on high; below it sit ~78 low ones, most of them checkouts
|
||||
# without persist-credentials: false, left for a later pass.
|
||||
- name: zizmor
|
||||
run: zizmor --min-severity=medium .github/
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
# zizmor configuration -- https://docs.zizmor.sh/configuration/
|
||||
# see .github/workflows/workflows_lint.yml for how CI invokes it
|
||||
|
||||
rules:
|
||||
unpinned-uses:
|
||||
config:
|
||||
policies:
|
||||
# this repo pins actions to a release tag and lets dependabot
|
||||
# (.github/dependabot.yml) move them, rather than pinning to a commit
|
||||
# hash. ref-pin requires a ref of some kind and accepts either a tag
|
||||
# or a branch, so `@master` passes this as well; hash-pin is what would
|
||||
# reject it, and nothing here asks for a tag specifically.
|
||||
"*": ref-pin
|
||||
Reference in New Issue
Block a user