Skip to content

ci: pin lint tools and drop unused deploy context input - #1

Merged
MarshallOfSound merged 2 commits into
mainfrom
sam/pin-ci-tools
Sep 26, 2026
Merged

MarshallOfSound merged 2 commits into
mainfrom
sam/pin-ci-tools

Conversation

@MarshallOfSound

@MarshallOfSound MarshallOfSound commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

CI on main can't start because zizmorcore/zizmor-action@<pin-me> isn't a SHA and org policy rejects anything unpinned. This pins zizmor-action to v0.6.4 and the actionlint image to 1.7.12 by its multi-arch digest.

Also drops the context input from the deploy workflow. The org zizmor check flags context: ${{ inputs.context }} on build-push-action as template injection, and nothing sets it anyway, so it now just builds from the repo root (same as the old default).

Clean locally with actionlint 1.7.12 and zizmor 1.23.1 (the org's config) and 1.24.1.

The lint job couldn't start because zizmor-action was still referenced by a
placeholder, and org policy only allows actions pinned to a full commit SHA.
Pin zizmor-action to v0.6.4 and the actionlint image to 1.7.12 by digest.
@MarshallOfSound
MarshallOfSound requested a review from a team as a code owner September 26, 2026 01:17
zizmor flags passing a workflow input straight into build-push-action's
context as template injection. Nothing sets the input, so build from the repo
root instead. Callers see no change, since the default was already ".".
@MarshallOfSound MarshallOfSound changed the title ci: pin actionlint and zizmor-action ci: pin lint tools and drop unused deploy context input Sep 26, 2026
@MarshallOfSound
MarshallOfSound enabled auto-merge (squash) September 26, 2026 01:30
@MarshallOfSound
MarshallOfSound merged commit 748c6f6 into main Sep 26, 2026
6 checks passed
@MarshallOfSound
MarshallOfSound deleted the sam/pin-ci-tools branch September 26, 2026 01:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants