Remove misleading label example #38
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow runs on every repository with the custom property `crabwatch` set to `true`. | |
| name: Crabwatch | |
| on: | |
| pull_request: | |
| # merge_group required for repositories that use merge queues | |
| # https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#merge_group | |
| merge_group: | |
| types: [ checks_requested ] | |
| permissions: {} | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| zizmor: | |
| name: Run zizmor | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: About Crabwatch | |
| shell: bash | |
| run: | | |
| cat <<'EOF' | |
| Crabwatch (https://github.com/rust-lang/crabwatch) audits GitHub Actions workflows across Rust project repositories using zizmor. | |
| If you encounter issues, ask for help in #t-infra: https://rust-lang.zulipchat.com/#narrow/stream/242791-t-infra | |
| EOF | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| persist-credentials: false | |
| - name: Download crabwatch zizmor config | |
| shell: bash | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| gh api repos/rust-lang/crabwatch/contents/zizmor-policy.yml \ | |
| -H "Accept: application/vnd.github.raw+json" > "$RUNNER_TEMP/zizmor-policy.yml" | |
| # Apply this repository's overrides to the default configuration. | |
| # zizmor-action runs zizmor in a container that mounts only the | |
| # workspace, so the config must be written inside it. | |
| yq --exit-status \ | |
| '.default * (.repositories[strenv(GITHUB_REPOSITORY)] // {})' \ | |
| "$RUNNER_TEMP/zizmor-policy.yml" > crabwatch-zizmor.yml | |
| echo "::group::Effective zizmor configuration for $GITHUB_REPOSITORY" | |
| cat crabwatch-zizmor.yml | |
| echo "::endgroup::" | |
| - name: Run zizmor | |
| # A missing or empty root .github directory has nothing to audit. | |
| if: ${{ hashFiles('.github/**') != '' }} | |
| uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4 | |
| with: | |
| advanced-security: false | |
| config: crabwatch-zizmor.yml | |
| # Only lint the root .github directory. | |
| # Ignore nested .github directories because they can belong to | |
| # vendored projects or test fixtures. | |
| inputs: .github/ | |
| # Don't fail on repositories without GitHub Actions workflows. | |
| fail-on-no-inputs: false | |
| persona: pedantic |