Skip to content

Remove misleading label example #38

Remove misleading label example

Remove misleading label example #38

# This workflow runs on every repository with the custom property `crabwatch` set to `true`.
name: Crabwatch
on:
pull_request:
# merge_group required for repositories that use merge queues
# https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#merge_group
merge_group:
types: [ checks_requested ]
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
cancel-in-progress: true
jobs:
zizmor:
name: Run zizmor
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: About Crabwatch
shell: bash
run: |
cat <<'EOF'
Crabwatch (https://github.com/rust-lang/crabwatch) audits GitHub Actions workflows across Rust project repositories using zizmor.
If you encounter issues, ask for help in #t-infra: https://rust-lang.zulipchat.com/#narrow/stream/242791-t-infra
EOF
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Download crabwatch zizmor config
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: |
gh api repos/rust-lang/crabwatch/contents/zizmor-policy.yml \
-H "Accept: application/vnd.github.raw+json" > "$RUNNER_TEMP/zizmor-policy.yml"
# Apply this repository's overrides to the default configuration.
# zizmor-action runs zizmor in a container that mounts only the
# workspace, so the config must be written inside it.
yq --exit-status \
'.default * (.repositories[strenv(GITHUB_REPOSITORY)] // {})' \
"$RUNNER_TEMP/zizmor-policy.yml" > crabwatch-zizmor.yml
echo "::group::Effective zizmor configuration for $GITHUB_REPOSITORY"
cat crabwatch-zizmor.yml
echo "::endgroup::"
- name: Run zizmor
# A missing or empty root .github directory has nothing to audit.
if: ${{ hashFiles('.github/**') != '' }}
uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
with:
advanced-security: false
config: crabwatch-zizmor.yml
# Only lint the root .github directory.
# Ignore nested .github directories because they can belong to
# vendored projects or test fixtures.
inputs: .github/
# Don't fail on repositories without GitHub Actions workflows.
fail-on-no-inputs: false
persona: pedantic