Skip to content

chore: add zizmor to the repo - #794

Open
rwaskiewicz wants to merge 1 commit into
mainfrom
rw/zizmor
Open

chore: add zizmor to the repo#794
rwaskiewicz wants to merge 1 commit into
mainfrom
rw/zizmor

Conversation

@rwaskiewicz

@rwaskiewicz rwaskiewicz commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Asana task: Add Zizmor to screenplay

Description

This commit adds zizmor to the repo. Doing so entails to components:

  1. Adding a new workflow to run zizmor when workflow files are edited
  2. Updating existing workflows to be compliant with the pedantic persona provided by zizmor

For this repository, the latter consisted of:

  1. Pinning actions used. Most actions were up to date already, making this action largely a no-op. Version comment strings have been updated
    to ensure they do not use major version only tags (e.g. v5), as these
    can cause issues should the tag move to a new version.
  2. Updating permissions so actions use have the least amount of permission when running
  3. Justifying permissions via comments
  4. Pinning the Postgres image used. The version was selected to match what is deployed to AWS at the time of this writing.
  • For features with a design/UX component, deployed branch to dev-green and let product know it's ready for review.

This commit adds zizmor to the repo. Doing so entails to components:
1. Adding a new workflow to run zizmor when workflow files are edited
2. Updating existing workflows to be compliant with the pedantic persona
provided by zizmor

For this repository, the latter consisted of:
1. Pinning actions used. Most actions were up to date already, making
this action largely a no-op. Version comment strings have been updated
 to ensure they do not use major version only tags (e.g. `v5`), as these
 can cause issues should the tag move to a new version.
2. Updating permissions so actions use have the least amount of
permission when running
3. Justifying permissions via comments
4. Pinning the Postgres image used to match the version that is deployed
in RDS at the time of this writing
@rwaskiewicz
rwaskiewicz marked this pull request as ready for review July 30, 2026 14:55
@rwaskiewicz
rwaskiewicz requested a review from a team as a code owner July 30, 2026 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant