diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 666c181..7a6dc3a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -9,11 +9,16 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true +permissions: + contents: read + jobs: ci: runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 + with: + persist-credentials: false - uses: voidzero-dev/setup-vp@1b32467adbe183473499fd9d5d372c3ed9641754 # v1.18.0 with: @@ -34,14 +39,21 @@ jobs: - run: vp run ts-compatibility - actionlint: + workflows: runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 + with: + persist-credentials: false # The versions pinned in mise.toml, so CI lints with the ones the hook runs. - uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3.6.3 with: - install_args: actionlint shellcheck + install_args: actionlint shellcheck zizmor - run: actionlint + + # The token enables the audits that query GitHub, such as known-vulnerable actions. + - run: zizmor .github/workflows + env: + GH_TOKEN: ${{ github.token }} diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index cba5558..4b7b69a 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -26,12 +26,17 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true +permissions: + contents: read + jobs: # The same build the release runs, so a broken book fails the PR and not the tag. build: runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 + with: + persist-credentials: false - uses: voidzero-dev/setup-vp@1b32467adbe183473499fd9d5d372c3ed9641754 # v1.18.0 with: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0451aa2..507097e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -4,6 +4,8 @@ on: push: tags: ["v*"] +permissions: {} + jobs: release: runs-on: ubuntu-latest @@ -14,11 +16,12 @@ jobs: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 with: fetch-depth: 0 # needed to check the tag is an ancestor of main + persist-credentials: false + # No cache in this workflow: a cache another ref wrote must not reach what a tag publishes. - uses: voidzero-dev/setup-vp@1b32467adbe183473499fd9d5d372c3ed9641754 # v1.18.0 with: node-version: "24" - cache: true registry-url: "https://registry.npmjs.org" # setup-vp puts `vp` on PATH but not pnpm, which the publish step needs. @@ -72,14 +75,17 @@ jobs: group: gh-pages # two releases must not push the site at once steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 + with: + persist-credentials: false - uses: voidzero-dev/setup-vp@1b32467adbe183473499fd9d5d372c3ed9641754 # v1.18.0 with: node-version: "24" - cache: true # mdbook and mdbook-linkcheck2, pinned in mise.toml. - uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3.6.3 + with: + cache: false - run: vp install @@ -106,10 +112,14 @@ jobs: node docs/tools/version-index/index.ts site touch site/.nojekyll + # The checkout keeps no credentials, so the token reaches this step alone and not the + # dependencies `vp install` runs. - name: Push the site run: | git -C site add --all git -C site -c user.name="github-actions[bot]" \ -c user.email="41898282+github-actions[bot]@users.noreply.github.com" \ commit --message "docs: publish $GITHUB_REF_NAME" - git -C site push origin HEAD:gh-pages + git -C site push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:gh-pages + env: + GH_TOKEN: ${{ github.token }} diff --git a/mise.lock b/mise.lock index aedef2a..023eee3 100644 --- a/mise.lock +++ b/mise.lock @@ -224,3 +224,44 @@ url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/2790 checksum = "sha256:8a4e35ab0b331c85d73567b12f2a444df187f483e5079ceffa6bda1faa2e740e" url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.zip" url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/279056944" + +[[tools.zizmor]] +version = "1.30.1" +backend = "aqua:zizmorcore/zizmor" +specifiers = ["1.30.1"] + +[tools.zizmor."platforms.linux-arm64"] +checksum = "sha256:7ff1dce33bdd18fd2a4affe63bdd47efcccca97b2cec1c1863ec26e9e2647540" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-aarch64-unknown-linux-gnu.tar.gz" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067643" +provenance = "github-attestations" + +[tools.zizmor."platforms.linux-arm64-musl"] +provenance = "github-attestations" + +[tools.zizmor."platforms.linux-x64"] +checksum = "sha256:e65324f4430c2717591937edcec90ccbefaf14c174f8ec9415e03ca875b46e1a" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-x86_64-unknown-linux-gnu.tar.gz" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067642" +provenance = "github-attestations" + +[tools.zizmor."platforms.linux-x64-musl"] +provenance = "github-attestations" + +[tools.zizmor."platforms.macos-arm64"] +checksum = "sha256:e28d22b087f9ebb8d99da6e740d348c930f559961c7c3f12badda54f882195a2" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-aarch64-apple-darwin.tar.gz" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067640" +provenance = "github-attestations" + +[tools.zizmor."platforms.macos-x64"] +checksum = "sha256:10e6b18b11ea07e515a16f0f0518c7b07527bc9977c1fd5698181ce7f3554202" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-x86_64-apple-darwin.tar.gz" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067641" +provenance = "github-attestations" + +[tools.zizmor."platforms.windows-x64"] +checksum = "sha256:b183b1e996eddfab9659f1e9b46e059f1ef1cf984a1f14e5da09f7876a4b3a1c" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-x86_64-pc-windows-msvc.zip" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067645" +provenance = "github-attestations" diff --git a/mise.toml b/mise.toml index 81450ff..26b9732 100644 --- a/mise.toml +++ b/mise.toml @@ -8,6 +8,7 @@ pinact = "5.0.0" actionlint = "1.7.12" # actionlint runs it over each `run:` script. shellcheck = "0.11.0" +zizmor = "1.30.1" [settings] lockfile = true diff --git a/vite.config.ts b/vite.config.ts index d4c3391..dc6ed83 100644 --- a/vite.config.ts +++ b/vite.config.ts @@ -5,7 +5,7 @@ import lint from "./oxlint.config.ts"; export default defineConfig({ staged: { "*": "vp check --fix", - ".github/workflows/*.yml": "actionlint", + ".github/workflows/*.yml": ["actionlint", "zizmor --offline"], }, pack: { // Named, so the import path is the name a user writes rather than where the file sits.