Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The repository is public now, so the zizmor action may upload its findings to
code scanning. The workflow carried a note saying to switch
advanced-securityon once that happened.
Following that note literally would have broken every push to main. The action
treats
advanced-securityandannotationsas mutually exclusive, and theworkflow had
annotations: truehardcoded, soaction.shcallsdieon"Mutually exclusive options" before zizmor ever runs:
So both options now switch on the event instead of one of them being fixed:
That keeps the annotations the workflow already asked for.
Claude-Observability-Pluginand
opencode-observability-pluginsolved the same conflict by droppingannotationsentirely, so their zizmor runs give no inline feedback on a pullrequest at all. Worth a follow-up in those two repositories.
The upload step is
github/codeql-action/upload-sarif, which needssecurity-events: write. The job only hadcontents: read, so that permissionand
actions: readcome along. Both match the two sibling repositories.Both expressions are written in the same
<condition> && 'true' || 'false'shape on purpose. The inverted
&& 'false' || 'true'form happens to work onlybecause a non-empty string is truthy in Actions expressions, which zizmor's own
unsound-ternaryaudit exists to catch.Verification
zizmor v1.30.1 run over this branch in the same container image CI uses: