From f8929cbb2912c4b7645d97f1259a8d779cd91398 Mon Sep 17 00:00:00 2001 From: Jeff Dickey <216188+jdx@users.noreply.github.com> Date: Wed, 9 Sep 2026 21:05:39 -0500 Subject: [PATCH 1/2] chore(ci): use self-repository workflow references --- .github/workflows/test.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 65c81898b..7fe75206c 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -12,7 +12,7 @@ jobs: if: ${{ github.actor == 'jdx' && (github.event_name != 'pull_request' || (github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.user.login == 'jdx')) }} permissions: contents: read - uses: ./.github/workflows/test-impl.yml + uses: $/.github/workflows/test-impl.yml with: trusted: true @@ -20,7 +20,7 @@ jobs: if: ${{ github.actor != 'jdx' || (github.event_name == 'pull_request' && (github.event.pull_request.head.repo.full_name != github.repository || github.event.pull_request.user.login != 'jdx')) }} permissions: contents: read - uses: ./.github/workflows/test-impl.yml + uses: $/.github/workflows/test-impl.yml with: trusted: false From b7a575b023377efee5d88bc43113192de99da1ab Mon Sep 17 00:00:00 2001 From: Jeff Dickey <216188+jdx@users.noreply.github.com> Date: Fri, 11 Sep 2026 14:37:51 -0500 Subject: [PATCH 2/2] chore(ci): replace actionlint with zizmor --- .cursor/install.sh | 2 +- .github/actionlint.yaml | 22 -------------------- mise.lock | 46 ----------------------------------------- mise.toml | 3 --- 4 files changed, 1 insertion(+), 72 deletions(-) delete mode 100644 .github/actionlint.yaml diff --git a/.cursor/install.sh b/.cursor/install.sh index d079ba10c..ae24db78f 100755 --- a/.cursor/install.sh +++ b/.cursor/install.sh @@ -8,7 +8,7 @@ set -euo pipefail export PATH="$HOME/.local/bin:$HOME/.cargo/bin:$PATH" # Trust the repo's mise config and install every pinned tool from mise.toml -# (go, node, python, prettier, actionlint, insta, shellcheck, ...). Idempotent: +# (go, node, python, prettier, insta, shellcheck, ...). Idempotent: # already-present tools are a fast no-op. mise trust --yes mise install diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml deleted file mode 100644 index d2e42abce..000000000 --- a/.github/actionlint.yaml +++ /dev/null @@ -1,22 +0,0 @@ -self-hosted-runner: - # Labels of self-hosted runner in array of strings. - labels: - - jdx-perf-v1 - - bamboo-perf - - macos-14 - - namespace-profile-endev-linux-amd64;overrides.cache-tag=cache - - buildjet-32vcpu-ubuntu-2204-arm - - buildjet-16vcpu-ubuntu-2204-arm - - buildjet-8vcpu-ubuntu-2204-arm - - buildjet-4vcpu-ubuntu-2204-arm - - buildjet-2vcpu-ubuntu-2204-arm - - buildjet-32vcpu-ubuntu-2204 - - buildjet-16vcpu-ubuntu-2204 - - buildjet-8vcpu-ubuntu-2204 - - buildjet-4vcpu-ubuntu-2204 - - buildjet-2vcpu-ubuntu-2204 - -# Configuration variables in array of strings defined in your repository or -# organization. `null` means disabling configuration variables check. -# Empty array means no configuration variable is allowed. -config-variables: null diff --git a/mise.lock b/mise.lock index 80611611b..a85d4cf19 100644 --- a/mise.lock +++ b/mise.lock @@ -1,51 +1,5 @@ # @generated - this file is auto-generated by `mise lock` https://mise.en.dev/dev-tools/mise-lock.html -[[tools.actionlint]] -version = "1.7.12" -backend = "aqua:rhysd/actionlint" - -[tools.actionlint."platforms.linux-arm64"] -checksum = "sha256:325e971b6ba9bfa504672e29be93c24981eeb1c07576d730e9f7c8805afff0c6" -url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_arm64.tar.gz" -url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924897" -provenance = "github-attestations" - -[tools.actionlint."platforms.linux-arm64-musl"] -checksum = "sha256:325e971b6ba9bfa504672e29be93c24981eeb1c07576d730e9f7c8805afff0c6" -url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_arm64.tar.gz" -url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924897" -provenance = "github-attestations" - -[tools.actionlint."platforms.linux-x64"] -checksum = "sha256:8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8" -url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz" -url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924896" -provenance = "github-attestations" - -[tools.actionlint."platforms.linux-x64-musl"] -checksum = "sha256:8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8" -url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz" -url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924896" -provenance = "github-attestations" - -[tools.actionlint."platforms.macos-arm64"] -checksum = "sha256:aba9ced2dee8d27fecca3dc7feb1a7f9a52caefa1eb46f3271ea66b6e0e6953f" -url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_darwin_arm64.tar.gz" -url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924893" -provenance = "github-attestations" - -[tools.actionlint."platforms.macos-x64"] -checksum = "sha256:5b44c3bc2255115c9b69e30efc0fecdf498fdb63c5d58e17084fd5f16324c644" -url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_darwin_amd64.tar.gz" -url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924880" -provenance = "github-attestations" - -[tools.actionlint."platforms.windows-x64"] -checksum = "sha256:6e7241b51e6817ea6a047693d8e6fed13b31819c9a0dd6c5a726e1592d22f6e9" -url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_windows_amd64.zip" -url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924919" -provenance = "github-attestations" - [[tools."aqua:mitsuhiko/insta"]] version = "1.48.0" backend = "aqua:mitsuhiko/insta" diff --git a/mise.toml b/mise.toml index 0be9662fc..1eb0ab121 100644 --- a/mise.toml +++ b/mise.toml @@ -10,7 +10,6 @@ mr-boxington = "1.8.3" # upgrade that changes how it samples would land in the series as a step change # in usage's numbers, indistinguishable from a real regression. Bump deliberately. "github:jdx/tak" = "v0.0.9" -actionlint = "latest" aube = "latest" communique = "latest" cargo-binstall = "1.22.0" @@ -88,8 +87,6 @@ run = [ [tasks.lint] depends = ['lint:*'] -[tasks."lint:actionlint"] -run = 'actionlint' [tasks."lint:prettier"] run = "prettier -c ." [tasks."lint:clippy"]