Skip to content

Remove frizbee.yml caller workflow#1582

Open
tashian wants to merge 6 commits intomasterfrom
carl/add-zizmor-frizbee
Open

Remove frizbee.yml caller workflow#1582
tashian wants to merge 6 commits intomasterfrom
carl/add-zizmor-frizbee

Conversation

@tashian
Copy link
Contributor

@tashian tashian commented Mar 5, 2026

Summary

Test plan

  • CI passes

🤖 Generated with Claude Code

tashian and others added 6 commits March 2, 2026 17:45
Add caller workflows for zizmor (security scanning) and frizbee
(action pinning verification). Fix zizmor findings where applicable
and add suppression config for intentional patterns.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Use unpinned-uses config.policies with org-level wildcard and
secrets-inherit disable instead of brittle per-line ignores that
break whenever workflow files change.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The ref-confusion audit crashes when workflows reference private
repos (e.g. internal-workflows, robot) because the GITHUB_TOKEN
lacks cross-repo access. Disable until zizmor supports scoping
this audit or we provide a broader token.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The caller workflow's permissions are the ceiling for reusable
workflows. The zizmor-action needs security-events: write to
upload SARIF results to GitHub Advanced Security.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Frizbee is being removed from the reusable actionci workflow
(smallstep/workflows#301). This standalone caller is no longer needed.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions github-actions bot added the needs triage Waiting for discussion / prioritization by team label Mar 5, 2026
@tashian tashian requested a review from azazeal March 5, 2026 22:14
@tashian tashian enabled auto-merge (squash) March 5, 2026 22:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs triage Waiting for discussion / prioritization by team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant