Skip to content

PYTHON-4962 Adopt zizmor GitHub Actions security scanner#312

Merged
blink1073 merged 2 commits intomongodb:masterfrom
blink1073:PYTHON-4962
Nov 12, 2024
Merged

PYTHON-4962 Adopt zizmor GitHub Actions security scanner#312
blink1073 merged 2 commits intomongodb:masterfrom
blink1073:PYTHON-4962

Conversation

@blink1073
Copy link
Member

No description provided.

@blink1073 blink1073 requested a review from NoahStapp November 11, 2024 19:29
@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@blink1073
Copy link
Member Author

I opened https://jira.mongodb.org/browse/MOTOR-1413 to track the failures.

@@ -0,0 +1,32 @@
name: GitHub Actions Security Analysis with zizmor 🌈
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this 🌈 emoji actually part of the name?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No it was part of the example in the zizmore repo

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Then can we remove it? It's a little distracting to have emojis in config files.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

uses: actions-rust-lang/setup-rust-toolchain@v1
- name: Get zizmor
run: cargo install zizmor
- name: Run zizmor 🌈
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here.

@blink1073 blink1073 requested a review from NoahStapp November 12, 2024 16:38
@blink1073 blink1073 merged commit cbef587 into mongodb:master Nov 12, 2024
@blink1073 blink1073 deleted the PYTHON-4962 branch November 12, 2024 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants