Skip to content

ci: upload zizmor findings to code scanning and keep pull request annotations - #44

Open
milanagm wants to merge 2 commits into
mainfrom
ci/zizmor-advanced-security
Open

milanagm wants to merge 2 commits into
mainfrom
ci/zizmor-advanced-security

Conversation

@milanagm

@milanagm milanagm commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

The repository is public now, so the zizmor action may upload its findings to
code scanning. The workflow carried a note saying to switch advanced-security
on once that happened.

Following that note literally would have broken every push to main. The action
treats advanced-security and annotations as mutually exclusive, and the
workflow had annotations: true hardcoded, so action.sh calls die on
"Mutually exclusive options" before zizmor ever runs:

if [[ "${GHA_ZIZMOR_ADVANCED_SECURITY}" == "true" && "${GHA_ZIZMOR_ANNOTATIONS}" == "true" ]]; then
    err "Mutually exclusive options: 'advanced-security: true' and 'annotations: true'"

So both options now switch on the event instead of one of them being fixed:

  • push to main — findings go to the security tab as SARIF
  • pull request and manual run — findings come back as inline annotations

That keeps the annotations the workflow already asked for. Claude-Observability-Plugin
and opencode-observability-plugin solved the same conflict by dropping
annotations entirely, so their zizmor runs give no inline feedback on a pull
request at all. Worth a follow-up in those two repositories.

The upload step is github/codeql-action/upload-sarif, which needs
security-events: write. The job only had contents: read, so that permission
and actions: read come along. Both match the two sibling repositories.

Both expressions are written in the same <condition> && 'true' || 'false'
shape on purpose. The inverted && 'false' || 'true' form happens to work only
because a non-empty string is truthy in Actions expressions, which zizmor's own
unsound-ternary audit exists to catch.

Verification

zizmor v1.30.1 run over this branch in the same container image CI uses:

No findings to report. Good job! (2 ignored, 3 suppressed)

@milanagm
milanagm requested a review from hassiebp September 23, 2026 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant