Skip to content

GHA: and harden existing workflows - #583

Open
guidoiaquinti wants to merge 1 commit into
vimalloc:mainfrom
guidoiaquinti:ci-lint-github-workflows
Open

guidoiaquinti wants to merge 1 commit into
vimalloc:mainfrom
guidoiaquinti:ci-lint-github-workflows

Conversation

@guidoiaquinti

Copy link
Copy Markdown
Contributor

Description

Adds a new GitHub Workflows CI workflow that lints and audits the workflows in this repo, and fixes everything it reported so it passes from the first run.

  • actionlint (v1.7.12): downloads the release, checks it against the published checksum, then runs it. Shell scripts in run: steps are also checked with shellcheck.
  • zizmor (v1.30.1): runs through uvx as zizmor --persona=auditor --collect=workflows .

Both jobs check out without keeping credentials, use read-only permissions, and pin their actions to commit SHAs. zizmor reported 45 findings in the current workflows. All of them are fixed or explicitly ignored.

Notes for maintainers

  • Check names change. Jobs now have names, so checks show up as e.g. Unit Tests (Python 3.10) instead of build (3.10). If branch protection requires the old names, those required checks need updating.
  • pypi environment. GitHub creates it automatically on the first release run, and the existing repository secrets (PYPI_USERNAME, PYPI_PASSWORD) still work in it. You can add protection rules to it, such as required reviewers, to guard releases.
  • Trusted publishing. Moving to PyPI trusted publishing would remove the long-lived PyPI credentials. It needs a trusted publisher set up on the PyPI project first, so it's left for a follow-up.
  • Keeping pins fresh. SHA pins don't update by themselves. A follow-up adding Dependabot for the github-actions ecosystem would keep them current.

@vimalloc

vimalloc commented Oct 5, 2026

Copy link
Copy Markdown
Owner

I'll take a closer look at this one in the coming days.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants