Skip to content

support repositories override - #73

Merged
marcoieni merged 1 commit into
mainfrom
support-repositories-override
Sep 30, 2026
Merged

marcoieni merged 1 commit into
mainfrom
support-repositories-override

Conversation

@marcoieni

@marcoieni marcoieni commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

We can't enable certain zizmor lints because some repositories don't pass them. In this PR, I add a mechanism to disable linters on certain repositories.

In this way, a repository doesn't block lints to be adopted in the organization.

Also enable archived-uses as an example of lint that is disabled on a repository level.

Design decisions

  • use yq also in the rust code to stress the same code of the crabwatch workflows (and avoid depending on a yaml crate)

Manual test

set repositories: {} in the configuration and run GITHUB_TOKEN=$(gh auth token) cargo run -- analyze --org rust-lang. You will see the following error:

Error

=== rust-lang/chalk ===
 INFO zizmor: 🌈 zizmor v1.30.1
 INFO audit: zizmor: 🌈 completed /Users/marco/Library/Caches/crabwatch/repos/rust-lang/chalk/627409a4735b8eeb9457583515d203013a59211b/.github/workflows/ci.yml
 INFO audit: zizmor: 🌈 completed /Users/marco/Library/Caches/crabwatch/repos/rust-lang/chalk/627409a4735b8eeb9457583515d203013a59211b/.github/workflows/publish.yml
warning[archived-uses]: action or reusable workflow from archived repository
  --> /Users/marco/Library/Caches/crabwatch/repos/rust-lang/chalk/627409a4735b8eeb9457583515d203013a59211b/.github/workflows/ci.yml:21:15
   |
20 |       - name: Install Rust toolchain
   |         ---------------------------- this step
21 |         uses: actions-rs/toolchain@v1
   |               ^^^^^^^^^^^^^^^^^^^^ repository is archived
   |
   = note: audit confidence → High
   = help: audit documentation → https://docs.zizmor.sh/audits/#archived-uses

warning[archived-uses]: action or reusable workflow from archived repository
  --> /Users/marco/Library/Caches/crabwatch/repos/rust-lang/chalk/627409a4735b8eeb9457583515d203013a59211b/.github/workflows/ci.yml:75:15
   |
74 |       - name: Install Rust toolchain
   |         ---------------------------- this step
75 |         uses: actions-rs/toolchain@v1
   |               ^^^^^^^^^^^^^^^^^^^^ repository is archived
   |
   = note: audit confidence → High
   = help: audit documentation → https://docs.zizmor.sh/audits/#archived-uses

warning[archived-uses]: action or reusable workflow from archived repository
  --> /Users/marco/Library/Caches/crabwatch/repos/rust-lang/chalk/627409a4735b8eeb9457583515d203013a59211b/.github/workflows/publish.yml:20:15
   |
19 |       - name: Install Rust toolchain
   |         ---------------------------- this step
20 |         uses: actions-rs/toolchain@v1
   |               ^^^^^^^^^^^^^^^^^^^^ repository is archived
   |
   = note: audit confidence → High
   = help: audit documentation → https://docs.zizmor.sh/audits/#archived-uses

warning[archived-uses]: action or reusable workflow from archived repository
  --> /Users/marco/Library/Caches/crabwatch/repos/rust-lang/chalk/627409a4735b8eeb9457583515d203013a59211b/.github/workflows/publish.yml:27:15
   |
26 |       - name: Install cargo-workspaces
   |         ------------------------------ this step
27 |         uses: actions-rs/install@v0.1
   |               ^^^^^^^^^^^^^^^^^^ repository is archived
   |
   = note: audit confidence → High
   = help: audit documentation → https://docs.zizmor.sh/audits/#archived-uses

4 findings: 0 informational, 0 low, 4 medium, 0 high

AI disclosure

I used GPT6-Astra and Fable 5.1 to generate this change. I reviewed its output and changed it where necessary.

@marcoieni
marcoieni force-pushed the support-repositories-override branch from 24b3b1b to 68d6af8 Compare September 29, 2026 08:01
Comment thread zizmor-policy.yml

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure if "zizmor-policy" is a good name.
For example, I think zizmor-config is confusing, because this now is a custom config we have.

An alternative solution would be keep zizmor-default.yml and put the overrides in a different files.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

zizmor-policy sounds good to me. Wouldn't splitting it mean the workflow and CLI have to merge two files?

Comment thread zizmor-policy.yml
Comment on lines +7 to +8
archived-uses:
disable: false

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it was disabled before 😎

@marcoieni
marcoieni force-pushed the support-repositories-override branch from 68d6af8 to 9440865 Compare September 29, 2026 08:15
Comment thread zizmor-policy.yml
rust-lang/chalk:
rules:
archived-uses:
disable: true

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

see rust-lang/chalk#834. It doesn't make sense to work on that PR because that repo is unused at the moment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It totally makes sense. Should I go ahead and close rust-lang/chalk#834 then? Chalk also has the adhoc-packages finding in publish.yml, so I guess the same applies there. I can add it to this override when I open the PR for #48.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great to know this approach resonates with you! Yes I think you can close that PR 👍

@marcoieni
marcoieni force-pushed the support-repositories-override branch 12 times, most recently from c511426 to 77a7f9c Compare September 29, 2026 15:12
@marcoieni
marcoieni marked this pull request as ready for review September 29, 2026 15:14

@ubiratansoares ubiratansoares left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a few comments

Comment thread src/config.rs Outdated
Comment on lines +72 to +83
fn effective_config(&self, repository: &str) -> anyhow::Result<String> {
yq(&[BUILD_CONFIG_EXPR], self.file.path(), repository)
}

/// Write `repository`'s zizmor configuration to a temporary file that is
/// deleted on drop.
///
/// `repository` is GitHub's canonical `owner/name`; override lookup is
/// case-sensitive.
pub(crate) fn write_config(&self, repository: &str) -> anyhow::Result<NamedTempFile> {
temp_file(&self.effective_config(repository)?)
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we go async here? If I did not miss anything, yq will block Tokio workers since it's running with std::process::Command

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done 👍

Comment on lines +44 to +46
echo "::group::Effective zizmor configuration for $GITHUB_REPOSITORY"
cat crabwatch-zizmor.yml
echo "::endgroup::"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since clicking the status check

Image

leads to a job summary, perhaps we could write this (also?) to the job summary, so developers see the config without having to expanding the logs.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If useful we could do this in another PR 👍

Comment thread .github/workflows/ci.yml Outdated
- name: Run tests
run: cargo test --workspace
run: |
# The config tests shell out to yq; fail early if the runner image drops it.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was not aware that yq comes pre-installed on GH runners. It seems it's been around since 2021, at this point feels unlike they will drop it from runner images

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reverted this change.

@marcoieni
marcoieni force-pushed the support-repositories-override branch from 759fd95 to a8562da Compare September 30, 2026 06:24
@marcoieni
marcoieni merged commit dfa5963 into main Sep 30, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants