Skip to content

Adopt GitHub's self-repository uses syntax, or disposition the 84 open zizmor self-repository alerts #271

Description

@devantler

🤖 Generated by the Agentic Engineer

Evidence

zizmor 1.30.0 added the self-repository audit, and since 2026-09-07 it reports 84 open code-scanning alerts
in this repository: 76 in .github/workflows/ci.yaml, 2 in active-release.yaml, and one each in
dependency-review.yaml, lint.yaml, run-dotnet-tests.yaml, scan-for-todo-comments.yaml,
update-agent-skills.yaml and validate-go-project.yaml. None has been fixed or dismissed. Every new uses: ./…
line adds another, and each one opens a review thread that has to be resolved by hand before merge (for example on
devantler-tech/actions#1232).

zizmor's documentation for the audit says GitHub now supports a self-repository form, uses: $/<path>, for in-repo
actions and reusable workflows.

Why it matters here

  • The documented benefit is security: unlike ./…, the $/ form does not depend on the runner's filesystem, so it
    cannot load an action cloned there by an earlier step, and GitHub treats it as pinned for policy enforcement.
  • That second point is what Revert tag-pin accommodations now that self-references are SHA-pinned actions#426 is waiting on (re-enabling sha_pinning_required for this repository).
  • The reusable workflows use a same-commit self-checkout into .devantler-tech-actions precisely because ./…
    resolves against the caller's workspace. If $/ resolves against the workflow's own repository and commit, that
    pattern and its cleanup step may become unnecessary.

Expected outcome

Either adopt $/ for in-repo references, or record why this repository keeps ./… and stop the alerts from
accumulating.

Acceptance criteria

  • Verify on a test job that $/<action> resolves to the same commit as the calling workflow, for a local job, a
    reusable workflow called from ci.yaml, and a reusable workflow called from another repository.
  • If it holds, migrate every flagged reference, update the self-reference rules in AGENTS.md, and keep the CI
    coverage-parity guard (it matches uses: ./<action>) working with the new form.
  • If it does not hold for some case, record which and why, and disposition those alerts with that reason.
  • Zero open self-repository alerts afterwards.

Rough size: M (the change is mechanical; proving resolution semantics per case is the real work).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions