Skip to content

add zizmor security GH action#754

Open
JessicaS11 wants to merge 2 commits intodevelopmentfrom
security
Open

add zizmor security GH action#754
JessicaS11 wants to merge 2 commits intodevelopmentfrom
security

Conversation

@JessicaS11
Copy link
Copy Markdown
Member

Thanks to @mfisher87 for creating this workflow for earthaccess and pointing me towards it to enhance our GitHub action security.

@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 15, 2026

Binder 👈 Launch a binder notebook on this branch for commit b09deef

I will automatically update this comment whenever this PR is modified

Binder 👈 Launch a binder notebook on this branch for commit 620b454

@github-advanced-security
Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@codecov
Copy link
Copy Markdown

codecov bot commented Apr 15, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 66.42%. Comparing base (86ab52a) to head (620b454).

❗ There is a different number of reports uploaded between BASE (86ab52a) and HEAD (620b454). Click for more details.

HEAD has 8 uploads less than BASE
Flag BASE (86ab52a) HEAD (620b454)
10 2
Additional details and impacted files
@@               Coverage Diff                @@
##           development     #754       +/-   ##
================================================
- Coverage        77.34%   66.42%   -10.92%     
================================================
  Files               42       37        -5     
  Lines             3231     3068      -163     
  Branches           401      393        -8     
================================================
- Hits              2499     2038      -461     
- Misses             600      961      +361     
+ Partials           132       69       -63     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copy link
Copy Markdown
Member

@weiji14 weiji14 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks Jessica, I've secretly used Zizmor at 3e1d75c to fix some issues already, but there are some remaining. Would you like to apply some more fixes directly in this PR, or in a follow-up PR? Happy to push those changes if you'd like.

Comment thread .github/workflows/zizmor.yml
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could probably combine this zizmor job into linter_actions.yml to reduce the number of GH Actions files, but up to you!

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I personally prefer shorter files or I end up struggling to find stuff, but that's just me, and this repo shouldn't be optimized for me 😁

@mfisher87 mfisher87 changed the title add zizmore security GH action add zizmor security GH action Apr 17, 2026
Co-authored-by: Wei Ji <23487320+weiji14@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants