Skip to content

chore(deps): bump zizmor-action to 0.6.3 - #3161

Merged
CTTY merged 2 commits into
apache:mainfrom
blackmwk:ir-3158
Sep 7, 2026
Merged

CTTY merged 2 commits into
apache:mainfrom
blackmwk:ir-3158

Conversation

@blackmwk

@blackmwk blackmwk commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Which issue does this PR close?

What changes are included in this PR?

  • Bump zizmorcore/zizmor-action from v0.6.2 to v0.6.3.
  • Migrate all 22 local action references from ./... to GitHub self-repository $/... references, resolving the new zizmor 1.30 audit.
  • Normalize $/... references only in the ASF allowlist job disposable checkout because the current checker recognizes ./..., but not $/..., as local. External action references remain unchanged and fully checked.

No zizmor audit is ignored or disabled.

Are these changes tested?

  • uvx zizmor@1.30.0 --strict-collection --persona=regular --collect=default --color=never . (no findings; 44 existing suppressions)
  • Exact pinned ASF allowlist checker against the current ASF allowlist (all 20 unique external action references accepted)
  • git diff --check upstream/main...HEAD

AI Disclosure

AI was used to inspect the #3158 CI failure, identify the ASF allowlist checker compatibility issue, apply the workflow updates, and draft this PR description. I reviewed the changes and validated them with the exact zizmor and ASF checker versions used by CI.

@CTTY CTTY left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lgtm!

@CTTY
CTTY merged commit 1deceb1 into apache:main Sep 7, 2026
21 checks passed
kevinjqliu pushed a commit that referenced this pull request Sep 10, 2026
* fix(ci): keep .github/actions in the source archive

`.github export-ignore` (#3189) hides `.github/actions` from repository
archives. GitHub resolves the `uses: $/...` self-repository references
introduced in #3161 by fetching such an archive, so every workflow that
uses a local composite action now fails at action resolution:

  Can't find 'action.yml', 'action.yaml' or 'Dockerfile' for action
  'apache/iceberg-rust/.github/actions/setup-builder@<sha>'

This breaks CI on main and on all open pull requests.

List the .github entries individually instead, so the repo-only files
#3189 targeted stay out of the release tarball while `.github/actions`
remains resolvable. A `-export-ignore` negation on the subdirectory does
not work: git does not descend into an export-ignored directory.

* comment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants