Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 6 additions & 5 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,16 +32,17 @@ jobs:

steps:
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false

- uses: docker/setup-buildx-action@v4.4.1

- uses: docker/login-action@v4.6.0
- uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- uses: docker/metadata-action@v6.2.0
- uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
id: meta
with:
images: ghcr.io/drumandbytes/github-actions-runner-exporter
Expand All @@ -51,7 +52,7 @@ jobs:
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}

- uses: docker/build-push-action@v7.4.0
- uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
id: build
with:
context: .
Expand Down
18 changes: 14 additions & 4 deletions .github/workflows/validate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,10 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

# Read-only token; no job here writes to the repo or reads other scopes.
permissions:
contents: read

jobs:
lint:
uses: drumandbytes/reusable-actions/.github/workflows/go-ci.yml@v1
Expand All @@ -30,10 +34,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false

- uses: docker/setup-buildx-action@v4.4.1

- uses: docker/build-push-action@v7.4.0
- uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
load: true
Expand All @@ -58,12 +63,17 @@ jobs:
-sS -f -o /dev/null http://localhost:9222/healthz
docker rm -f smoke-test

# Audit of this repo's own workflows; accepted findings are in
# .github/zizmor.yml.
zizmor:
uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1

# Single stable name for the org's required-status-check ruleset to point
# at, regardless of how the real jobs above are split or renamed.
required-checks-passed:
name: Required checks passed
runs-on: ubuntu-latest
needs: [lint, smoke-test]
needs: [lint, smoke-test, zizmor]
if: always()
steps:
- if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')
Expand Down
18 changes: 18 additions & 0 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# zizmor configuration, read by the zizmor job in validate.yml. Anything accepted
# here is accepted on purpose -- each entry says why.

rules:
unpinned-uses:
config:
policies:
# GitHub's own and the org's actions stay on tags (Dependabot moves
# them); third-party actions are SHA-pinned.
"actions/*": ref-pin
"drumandbytes/*": ref-pin
"*": hash-pin

dangerous-triggers:
ignore:
# workflow_run so Dependabot PRs get a token that can merge; never
# checks out PR code.
- auto-merge.yml
Loading