From 925f341efd1d9d361fb2bdb1221c2a8a69960ec4 Mon Sep 17 00:00:00 2001 From: Johannes Ewald Date: Wed, 23 Sep 2026 11:25:58 +0200 Subject: [PATCH 1/4] ci: Merge lint workflows into test workflow Run secretlint as a background step and zizmor inline in the test job instead of separate workflows. Drop the unused `actions: write` permission from the test job. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/lint-github-actions.yml | 35 -------------------- .github/workflows/lint-secrets.yml | 39 ----------------------- .github/workflows/test.yml | 29 ++++++++++++++++- 3 files changed, 28 insertions(+), 75 deletions(-) delete mode 100644 .github/workflows/lint-github-actions.yml delete mode 100644 .github/workflows/lint-secrets.yml diff --git a/.github/workflows/lint-github-actions.yml b/.github/workflows/lint-github-actions.yml deleted file mode 100644 index 8413d8d..0000000 --- a/.github/workflows/lint-github-actions.yml +++ /dev/null @@ -1,35 +0,0 @@ -name: 🔍 Lint GitHub Actions - -on: - push: - branches: - - main - - beta - paths: - - ".github/workflows/**/*.yml" - - ".github/workflows/**/*.yaml" - pull_request: - paths: - - ".github/workflows/**/*.yml" - - ".github/workflows/**/*.yaml" - workflow_dispatch: {} - -permissions: {} - -jobs: - lint-github-actions: - name: 🔍 Lint GitHub Actions - runs-on: ubuntu-latest - permissions: - contents: read - - steps: - - name: 📥 Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: 🌈 Run zizmor - uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 - with: - advanced-security: false diff --git a/.github/workflows/lint-secrets.yml b/.github/workflows/lint-secrets.yml deleted file mode 100644 index 982f082..0000000 --- a/.github/workflows/lint-secrets.yml +++ /dev/null @@ -1,39 +0,0 @@ -name: 🔍 Lint Secrets - -on: - push: - branches: - - main - - beta - pull_request: {} - workflow_dispatch: {} - -permissions: {} - -jobs: - lint-secrets: - name: 🔍 Lint Secrets - runs-on: ubuntu-latest - permissions: - contents: read - - steps: - - name: 📥 Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: 🔍 Run secretlint - shell: bash - run: | - set -euo pipefail - - secretlint_version="$(node -p "require('./package.json').devDependencies.secretlint")" - secretlint_version="${secretlint_version#^}" - secretlint_version="${secretlint_version#~}" - secretlint_version="${secretlint_version#v}" - - docker run --rm --network none \ - -v "${PWD}:${PWD}" -w "${PWD}" \ - "secretlint/secretlint:v${secretlint_version}" \ - secretlint --format github "**/*" diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 6e30691..5dfb5c5 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -16,7 +16,6 @@ jobs: runs-on: ubuntu-latest if: ${{ !contains(github.event.head_commit.message, '[skip ci]') }} permissions: - actions: write contents: read concurrency: @@ -29,6 +28,30 @@ jobs: with: persist-credentials: false + # Runs in the background while dependencies are installed. + # Uses the runner's preinstalled Node.js to read the secretlint version. + - name: 🔍 Lint secrets + id: lint-secrets + background: true + shell: bash + run: | + set -euo pipefail + + secretlint_version="$(node -p "require('./package.json').devDependencies.secretlint")" + secretlint_version="${secretlint_version#^}" + secretlint_version="${secretlint_version#~}" + secretlint_version="${secretlint_version#v}" + + docker run --rm --network none \ + -v "${PWD}:${PWD}" -w "${PWD}" \ + "secretlint/secretlint:v${secretlint_version}" \ + secretlint --format github "**/*" + + - name: 🌈 Lint GitHub Actions + uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 + with: + advanced-security: false + - name: 🟢 Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -67,3 +90,7 @@ jobs: CI: true run: | npm test + + # Background step failures are only reported at a wait step + - name: ⏳ Wait for secret lint + wait: [lint-secrets] From b1c25cc9ff1a7dfceb7385d34942c5a39b173fe3 Mon Sep 17 00:00:00 2001 From: Johannes Ewald Date: Wed, 23 Sep 2026 11:57:45 +0200 Subject: [PATCH 2/4] ci: Run zizmor as background step Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/test.yml | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 5dfb5c5..ab8eb22 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -28,7 +28,7 @@ jobs: with: persist-credentials: false - # Runs in the background while dependencies are installed. + # Linters run in the background while dependencies are installed. # Uses the runner's preinstalled Node.js to read the secretlint version. - name: 🔍 Lint secrets id: lint-secrets @@ -48,6 +48,8 @@ jobs: secretlint --format github "**/*" - name: 🌈 Lint GitHub Actions + id: lint-github-actions + background: true uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 with: advanced-security: false @@ -92,5 +94,5 @@ jobs: npm test # Background step failures are only reported at a wait step - - name: ⏳ Wait for secret lint - wait: [lint-secrets] + - name: ⏳ Wait for linters + wait: [lint-secrets, lint-github-actions] From 19c2a3912a977a5370e19510980f61b11b1e52b1 Mon Sep 17 00:00:00 2001 From: Johannes Ewald Date: Wed, 23 Sep 2026 11:57:51 +0200 Subject: [PATCH 3/4] =?UTF-8?q?test:=20DO=20NOT=20MERGE=20=E2=80=93=20add?= =?UTF-8?q?=20intentional=20lint=20violations?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fake Slack token for secretlint and an unpinned, injectable workflow for zizmor to preview how CI reports findings. Revert before merging. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/zizmor-violation-test.yml | 17 +++++++++++++++++ secretlint-violation-test.txt | 3 +++ 2 files changed, 20 insertions(+) create mode 100644 .github/workflows/zizmor-violation-test.yml create mode 100644 secretlint-violation-test.txt diff --git a/.github/workflows/zizmor-violation-test.yml b/.github/workflows/zizmor-violation-test.yml new file mode 100644 index 0000000..652637c --- /dev/null +++ b/.github/workflows/zizmor-violation-test.yml @@ -0,0 +1,17 @@ +# DO NOT MERGE: intentional zizmor violation to preview CI reporting. +# Only runs on manual dispatch so it never executes automatically. +name: 🚧 Zizmor violation test + +on: + workflow_dispatch: + inputs: + name: + description: "Name" + required: true + +jobs: + greet: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - run: echo "Hello ${{ github.event.inputs.name }}" diff --git a/secretlint-violation-test.txt b/secretlint-violation-test.txt new file mode 100644 index 0000000..b87176f --- /dev/null +++ b/secretlint-violation-test.txt @@ -0,0 +1,3 @@ +DO NOT MERGE: intentional secretlint violation to preview CI reporting. +This is a fake credential, not a real one. +DATABASE_URL=https://ci-preview-user:f4keP4ssw0rdForSecretlint@example.com/db From 74e788e4c674d265d915ffc890a8532c13050307 Mon Sep 17 00:00:00 2001 From: Johannes Ewald Date: Wed, 23 Sep 2026 13:40:10 +0200 Subject: [PATCH 4/4] =?UTF-8?q?Revert=20"test:=20DO=20NOT=20MERGE=20?= =?UTF-8?q?=E2=80=93=20add=20intentional=20lint=20violations"?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This reverts commit 19c2a39. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/zizmor-violation-test.yml | 17 ----------------- secretlint-violation-test.txt | 3 --- 2 files changed, 20 deletions(-) delete mode 100644 .github/workflows/zizmor-violation-test.yml delete mode 100644 secretlint-violation-test.txt diff --git a/.github/workflows/zizmor-violation-test.yml b/.github/workflows/zizmor-violation-test.yml deleted file mode 100644 index 652637c..0000000 --- a/.github/workflows/zizmor-violation-test.yml +++ /dev/null @@ -1,17 +0,0 @@ -# DO NOT MERGE: intentional zizmor violation to preview CI reporting. -# Only runs on manual dispatch so it never executes automatically. -name: 🚧 Zizmor violation test - -on: - workflow_dispatch: - inputs: - name: - description: "Name" - required: true - -jobs: - greet: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - - run: echo "Hello ${{ github.event.inputs.name }}" diff --git a/secretlint-violation-test.txt b/secretlint-violation-test.txt deleted file mode 100644 index b87176f..0000000 --- a/secretlint-violation-test.txt +++ /dev/null @@ -1,3 +0,0 @@ -DO NOT MERGE: intentional secretlint violation to preview CI reporting. -This is a fake credential, not a real one. -DATABASE_URL=https://ci-preview-user:f4keP4ssw0rdForSecretlint@example.com/db