Skip to content

fix(ci): resolve all zizmor findings and add zizmor pre-commit checks - #404

Merged
rapids-bot[bot] merged 10 commits into
rapidsai:mainfrom
gforsyth:securitize
May 7, 2026
Merged

rapids-bot[bot] merged 10 commits into
rapidsai:mainfrom
gforsyth:securitize

Conversation

@gforsyth

@gforsyth gforsyth commented May 5, 2026

Copy link
Copy Markdown
Contributor

Similar to upstream changes in shared-workflows, this PR cleans up and annotates all of the workflows and adds the zizmor linter to make sure changes are checked.

Part of rapidsai/build-planning#275

@gforsyth
gforsyth requested a review from a team as a code owner May 5, 2026 14:33
@gforsyth gforsyth added improvement Improves an existing functionality non-breaking Introduces a non-breaking change labels May 5, 2026
@gforsyth
gforsyth requested review from KyleFromNVIDIA and removed request for a team May 5, 2026 14:33

@jameslamb jameslamb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left some suggestions for your consideration, but I'm also comfortable with this being merged as-is if you think they're not worth implementing.

Comment thread .github/workflows/build-image.yaml Outdated
steps:
- name: Checkout
uses: actions/checkout@v6
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

This is v6.0.2 (https://github.com/actions/checkout/releases/tag/v6.0.2.

I think specifying that full tag might be useful for renovate's update logic? I'm not sure, but recommend erring on the side of pinning to a specific semver where it's available.

If nothing else, I think using the full version should mean the diff for the next automatic update will change the comment too, so we'll be able to tell the difference visually between 6.0.2 -> 6.0.3 and 6.0.2 -> 6.1.0.

Would you consider that for all of these?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, the tags vs. releases are weird -- I think our mutable refs are pointing at tags (one more reason not to use them) -- so it is 6.0.2 but it is also v6 (https://github.com/actions/checkout/releases/tag/v6) -- and I think they change what v6 refers to for point releases. I can update that.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree with your read, that's exactly right.

v6 gets updated every time a new v6.* is cut.

Comment thread .github/workflows/pr.yaml Outdated
with:
build_type: pull-request
secrets: inherit
secrets: inherit # zizmor: ignore[secrets-inherit]

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of secrets: inherit, would you consider explicitly defining which secrets need to get passed through in workflow_call calls?

Here's an example of that: rapidsai/shared-workflows#489 (though here we don't need the name and value separated, can just pass through the value directly).

That's tighter than secrets: inherit because it means that new secrets that become available to the repo aren't immediately accessible in the calling workflow.

I also think it has the nice side benefit of making the configuration flow a bit more explicit.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree it's better to explicilty define the secrets -- and because it's currently all implicit it's hard to trace out which secrets are needed.

I might defer this until we can create a general grammar for which shared workflows make use of which secrets and then take a pass to tighten up the secret passing.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have more thoughts on this after some spelunking but I think it should get written up somewhere else.

I'll take a pass on this PR, though, and tighten up the secrets usage where possible (it's largely not possible at the moment)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

xref rapidsai/build-infra#358

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Latest changes + that issue look good, thank you for that!

@jameslamb
jameslamb removed the request for review from KyleFromNVIDIA May 5, 2026 14:41
@jakirkham

Copy link
Copy Markdown
Member

Pulled the latest changes into this PR

This also reruns CI. Hoping this clears out the previous apt-get repo availability issues

@gforsyth

gforsyth commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

/merge

@rapids-bot
rapids-bot Bot merged commit 6a724ce into rapidsai:main May 7, 2026
387 checks passed
@gforsyth
gforsyth deleted the securitize branch May 7, 2026 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

improvement Improves an existing functionality non-breaking Introduces a non-breaking change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants