Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .github/workflows/auto-assign.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@ name: Auto Assign
on:
issues:
types: [opened]
pull_request_target:
# zizmor: ignore[dangerous-triggers] Assigns pull requests via the API
# only; never checks out or executes untrusted code.
pull_request_target:
types: [opened]
jobs:
run:
Expand Down
6 changes: 5 additions & 1 deletion .github/workflows/auto-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,9 @@ name: Dependabot Auto-Merge

# Never check out or execute pull-request content in this privileged workflow.
on:
# zizmor: ignore[dangerous-triggers] Never checks out or executes pull
# request content; merges via the GitHub API only after required checks pass
# and the head commit is pinned.
pull_request_target:
types: [opened, synchronize, reopened, ready_for_review]

Expand All @@ -13,8 +16,9 @@ jobs:
dependabot:
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 45
# The pull request author's login is authoritative for this check;
# github.actor would be spoofable and adds nothing on top of it.
if: >-
github.actor == 'dependabot[bot]' &&
github.event.pull_request.user.login == 'dependabot[bot]' &&
github.event.pull_request.base.ref == 'main' &&
github.event.pull_request.head.repo.full_name == github.repository
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/build-images.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,13 @@ on:
required: false
type: string
default: linux/amd64,linux/arm64
secrets:
# GHCR login token with package push rights.
GH_PACKAGE_TOKEN:
required: true
# Source-map upload token; only the web image build uses it.
SENTRY_AUTH_TOKEN:
required: false

jobs:
build:
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,11 @@ jobs:
permissions:
contents: read
packages: write
uses: ./.github/workflows/build-images.yml
secrets: inherit

uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported
secrets:
GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }}
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
with:
source_mode: released
version: ${{ inputs.version }}
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/helm-chart.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,8 @@ jobs:
validate:
permissions:
contents: read
uses: ./.github/workflows/helm-validate.yml

uses: ./.github/workflows/helm-validate.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported

publish:
if: github.ref == 'refs/heads/main' && inputs.version != ''
Expand Down
10 changes: 7 additions & 3 deletions .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -187,7 +187,8 @@ jobs:
verify:
name: Verify nightly build
if: ${{ github.ref == format('refs/heads/{0}', github.event.repository.default_branch) }}
uses: ./.github/workflows/ci.yml

uses: ./.github/workflows/ci.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported

publish-images:
name: Publish nightly images
Expand All @@ -196,8 +197,11 @@ jobs:
permissions:
contents: read
packages: write
uses: ./.github/workflows/build-images.yml
secrets: inherit

uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported
secrets:
GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }}
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
with:
source_mode: nightly
tags: |
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/pr-size-labeler.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
name: PR Size Labeler

on:
# zizmor: ignore[dangerous-triggers] Labels pull requests via the API;
# checks out only the trusted base-branch size configuration.
pull_request_target:
types: [opened, synchronize, reopened]

Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/publish-mcp.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,9 @@ jobs:
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: 24.19.0
cache: pnpm
# Publish workflows must not read cache content that a pull
# request could have poisoned (zizmor cache-poisoning).
package-manager-cache: false

- name: Install dependencies
run: pnpm install --frozen-lockfile
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/publish-planka-import.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,9 @@ jobs:
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: 24
cache: pnpm
# Publish workflows must not read cache content that a pull
# request could have poisoned (zizmor cache-poisoning).
package-manager-cache: false

- name: Install dependencies
run: pnpm install --frozen-lockfile
Expand Down
13 changes: 9 additions & 4 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -124,8 +124,11 @@ jobs:
permissions:
contents: read
packages: write
uses: ./.github/workflows/build-images.yml
secrets: inherit

uses: ./.github/workflows/build-images.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported
secrets:
GH_PACKAGE_TOKEN: ${{ secrets.GH_PACKAGE_TOKEN }}
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
with:
source_mode: planned
version: ${{ needs.plan.outputs.version }}
Expand All @@ -137,7 +140,8 @@ jobs:
if: ${{ !inputs.dry_run && needs.plan.outputs.version != '' }}
permissions:
contents: read
uses: ./.github/workflows/helm-validate.yml

uses: ./.github/workflows/helm-validate.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported

release:
name: Release
Expand Down Expand Up @@ -233,6 +237,7 @@ jobs:
permissions:
contents: read
packages: write
uses: ./.github/workflows/helm-chart.yml

uses: ./.github/workflows/helm-chart.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported
with:
version: ${{ needs.plan.outputs.version }}
3 changes: 2 additions & 1 deletion .github/workflows/ui-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,8 @@ jobs:
concurrency:
group: peekareq-${{ needs.authorize.outputs.pr }}
cancel-in-progress: true
uses: ./.github/workflows/ui-review-run.yml

uses: ./.github/workflows/ui-review-run.yml # zizmor: ignore[self-repository] $/-syntax not parsed by pinned actionlint v1.7.12; revisit when supported
with:
pr: ${{ needs.authorize.outputs.pr }}
model: ${{ needs.authorize.outputs.model }}
Expand Down
Loading