Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
joe4dev
marked this pull request as ready for review
September 28, 2026 12:51
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Our workflows are SHA-pinned (DEVX-978), but nothing audits them for the other common GitHub Actions weaknesses: persisted credentials, template injection, over-broad
GITHUB_TOKENscopes,secrets: inherit, and cache poisoning in the release job. zizmor catches these and is used in localstack-pro; this PR adds it and fixes what it currently finds.FYI: I fixed other violations previously such as pinning in #486 and #511
Solution
zizmor.ymlworkflow runs zizmor via the pre-commit hook on PRs, pushes tomain, and weekly (online audits compare pins against upstream, which can change without a commit). It fails on every finding at the default persona; the 10 accepted findings carry an inline# zizmor: ignore[<audit>] <reason>.revin.pre-commit-config.yamlis the single pin; CI installs pre-commit from.github/tools/requirements.txt. New Dependabotpre-commitandpipentries, plus a 7-day cooldown on all ecosystems (security updates exempt).persist-credentials: falseon every checkout that doesn't push.${{ }}moved intoenv:in the release-tag action and the integration result check.permissions:(workflow-level{}/contents: read, per-job grants). The weekly release'scijob grants exactly the scopesci.ymldeclares.secrets: inheritreplaced by passing onlyLOCALSTACK_AUTH_TOKEN; a direct tag push still sees all repo secrets.releasejob.uses: $/...for the local action and reusable workflow, so they run from the workflow's own commit rather than whatevercreate-release-tag.ymlchecked out.$/needs zizmor ≥ 1.29 locally; actionlint 1.7.12 doesn't understand it yet (not run in this repo).Testing
No tag or release was created; release-path tests ran as renamed copies on a scratch branch (push-triggered, create-tag job removed), since deleted.
$/call toci.ymlwith narrowed permissions (validated incl. the skippedrelease), andLOCALSTACK_AUTH_TOKENreaching the integration tests all passed.workflow_call.secretsblock declaring one secret, a direct push still sawPRO_ACCESS_TOKEN,NPM_AUTH_TOKENandLSTK_EXTENSIONS_READ_TOKEN, so the tag-pushreleasejob keeps its tokens.GITHUB_TOKENatcontents: read.zizmor.yml,trivy.yml,sync-labels.yml,ci.ymlall passed (one flaky Windows test,TestConfigLoadFailureRendersJSONEnvelope, passed on re-run).enforce-labels.yml(pull_request_targetrunsmain's copy),weekly-go-upgrade.yml(a branch dispatch would rewrite chore(go): weekly Go toolchain upgrade #469), the$/composite action (it pushes a tag), and the real release.Docs
Nothing user-facing: CI and contributor tooling only. CLAUDE.md notes the new pre-commit hook and how to reproduce the audit locally (
GH_TOKEN=$(gh auth token) pre-commit run zizmor --all-files).Review
Human review advised: it changes permissions and secrets in the release and publish workflows, which only the weekly release and a tag push fully exercise.
Todo
$/refs, new ecosystems)ignore[use-trusted-publishing]Closes DEVX-1144
🤖 Generated with Claude Code