fix(ci): resolve all zizmor findings and add zizmor pre-commit checks - #455
Conversation
Greptile SummaryThis PR hardens all GitHub Actions workflows against supply-chain and privilege-escalation risks by adding default-deny
Confidence Score: 5/5All changes are additive security hardening with no functional logic altered; safe to merge. The diff touches only workflow permission and secret declarations. Every changed job still calls the same reusable workflows with the same inputs; the only behavioral difference is a narrower privilege scope. The No files require special attention; all changes are straightforward permission annotations. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Workflow trigger] --> B["Top-level permissions: {} (default-deny)"]
B --> C{Job type}
C -->|Build/Test jobs| D["secrets: inherit + zizmor ignore\nJob-level permissions:\nactions,contents,id-token,packages,pull-requests"]
C -->|Upload/Publish jobs| E["Explicit named credentials only\nJob-level permissions:\nactions,contents,id-token,packages,pull-requests"]
D --> G[Reusable shared-workflow call]
E --> G
H["pre-commit: zizmor v1.24.1"] -->|lint on commit| I["zizmor.yml policy\nrapidsai/* any pin\neveryone else hash-pin"]
Reviews (1): Last reviewed commit: "fix(ci): add dangerous trigger comment a..." | Re-trigger Greptile |
|
Woohoo! Flowchart! |
|
/merge |
Similar to upstream changes in
shared-workflows, this PR cleans up and annotates all of the workflows and adds thezizmorlinter to make sure changes are checked.Part of rapidsai/build-planning#275