Skip to content

fix(ci): resolve all zizmor findings and add zizmor pre-commit checks - #455

Merged
rapids-bot[bot] merged 5 commits into
rapidsai:mainfrom
gforsyth:securitize
May 7, 2026
Merged

rapids-bot[bot] merged 5 commits into
rapidsai:mainfrom
gforsyth:securitize

Conversation

@gforsyth

@gforsyth gforsyth commented May 7, 2026

Copy link
Copy Markdown
Contributor

Similar to upstream changes in shared-workflows, this PR cleans up and annotates all of the workflows and adds the zizmor linter to make sure changes are checked.

Part of rapidsai/build-planning#275

@gforsyth
gforsyth requested a review from a team as a code owner May 7, 2026 19:47
@gforsyth
gforsyth requested a review from jameslamb May 7, 2026 19:47
@gforsyth gforsyth added improvement Improves an existing functionality non-breaking Introduces a non-breaking change labels May 7, 2026
@greptile-apps

greptile-apps Bot commented May 7, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR hardens all GitHub Actions workflows against supply-chain and privilege-escalation risks by adding default-deny permissions: {} at the workflow level, explicit least-privilege per-job permissions, and replacing broad secrets: inherit with explicit secret maps where zizmor cannot be suppressed. It also SHA-pins the third-party nv-gha-runners/get-pr-info action and introduces a zizmor pre-commit hook to prevent regressions.

  • Permissions lockdown: Every workflow gains a top-level permissions: {} default-deny block; each job then declares only the permissions it actually needs (actions: read, contents: read, id-token: write, packages: read, pull-requests: read).
  • Explicit credentials: Upload and publish jobs now pass only named credentials instead of inheriting the full store; remaining secrets: inherit usages are annotated with # zizmor: ignore[secrets-inherit].
  • Ongoing enforcement: .github/zizmor.yml configures pin-policy exceptions for trusted rapidsai/* namespaces, and the new zizmor-pre-commit hook at v1.24.1 ensures any future workflow edits are automatically checked.

Confidence Score: 5/5

All changes are additive security hardening with no functional logic altered; safe to merge.

The diff touches only workflow permission and secret declarations. Every changed job still calls the same reusable workflows with the same inputs; the only behavioral difference is a narrower privilege scope. The pull_request_target suppression is well-documented and the job does not check out PR code.

No files require special attention; all changes are straightforward permission annotations.

Important Files Changed

Filename Overview
.github/workflows/build.yaml Adds top-level permissions: {} default-deny, per-job explicit permissions, and replaces secrets: inherit with explicit secret maps for upload/publish jobs; remaining secrets: inherit usages are annotated with zizmor ignores.
.github/workflows/pr.yaml Adds permissions: {} default-deny, per-job explicit permissions, removes secrets: inherit from jobs that don't need it, and SHA-pins nv-gha-runners/get-pr-info.
.github/workflows/test.yaml Adds top-level permissions: {} and per-job explicit permissions; all secrets: inherit usages annotated with zizmor ignores.
.github/workflows/trigger-breaking-change-alert.yaml Annotates pull_request_target trigger with a zizmor ignore and explanatory comment, adds permissions: {} default-deny, and replaces secrets: inherit with an explicit single-secret map.
.github/zizmor.yml New zizmor config allowing any pin policy for rapidsai/* namespaces while requiring hash-pins for all other third-party actions.
.pre-commit-config.yaml Adds zizmor-pre-commit hook at v1.24.1 to enforce workflow security checks on every commit.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[Workflow trigger] --> B["Top-level permissions: {} (default-deny)"]
    B --> C{Job type}
    C -->|Build/Test jobs| D["secrets: inherit + zizmor ignore\nJob-level permissions:\nactions,contents,id-token,packages,pull-requests"]
    C -->|Upload/Publish jobs| E["Explicit named credentials only\nJob-level permissions:\nactions,contents,id-token,packages,pull-requests"]
    D --> G[Reusable shared-workflow call]
    E --> G
    H["pre-commit: zizmor v1.24.1"] -->|lint on commit| I["zizmor.yml policy\nrapidsai/* any pin\neveryone else hash-pin"]
Loading

Reviews (1): Last reviewed commit: "fix(ci): add dangerous trigger comment a..." | Re-trigger Greptile

@jameslamb jameslamb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎉

@gforsyth gforsyth added improvement Improves an existing functionality and removed improvement Improves an existing functionality labels May 7, 2026
@gforsyth

gforsyth commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

Woohoo! Flowchart!

@gforsyth

gforsyth commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

/merge

@rapids-bot
rapids-bot Bot merged commit 93849d2 into rapidsai:main May 7, 2026
90 checks passed
@gforsyth
gforsyth deleted the securitize branch May 8, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

improvement Improves an existing functionality non-breaking Introduces a non-breaking change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants