← Back to issue list

ci: add zizmor actions permission

View original Github issue

Metadata

Project
craft-parts
Number
#1670
Type
pull request
State
merged
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged after approval by two reviewers. Adds required GitHub Actions permissions for the zizmor security scanner to enable CI checks. The change is minimal, modifying a single file with one line addition.

Suggested action:

No scores available.

Issue body

- [ ] Have you followed the guidelines for contributing? - [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `make lint && make test`? - [ ] Have you added an entry to the changelog (`docs/reference/changelog.rst`)? ---

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged after approval by two reviewers. Adds required GitHub Actions permissions for the zizmor security scanner to enable CI checks. The change is minimal, modifying a single file with one line addition.
qwen/qwen3.6-35b-a3b
Staleness: 5
Complexity: 5
Confidence: 95
needs review Adds zizmor GitHub Actions permission to CI configuration. Approved by one reviewer, CI checks are passing or pending, and the change is minimal (+1/-0 lines).
qwen/qwen3.6-35b-a3b
Staleness: 5
Complexity: 5
Confidence: 95
needs review Adds zizmor Actions permission to CI workflow. All checks passing, approved by one reviewer, ready to merge.
qwen/qwen3.6-35b-a3b
Staleness: 5
Complexity: 5
Confidence: 90
needs review Adds zizmor GitHub Actions permission to CI workflow. PR is fresh, all CI checks pass, awaiting maintainer review.

Update history

Date Change
updated
updated
created

Related issues

Issue Project State Summary Similarity
#591 ci: add zizmor actions permission starbase merged Merged to update GitHub Actions permissions for the zizmor security scanner. Approved by one reviewer with all CI checks passing.
95%
#251 ci: update permissions for zizmor craft-archives merged Merged after approval and passing CI checks. Updated GitHub Actions permissions for the zizmor security scanner with a single-line configuration change.
91%
#1163 ci: add zizmor actions permission craft-application merged Merged a single-line update to grant zizmor actions permissions in the CI configuration. Approved by one reviewer and passed all security scans and tests.
91%
#168 ci: update required permissions for zizmor starflow merged Merged CI workflow update adding required permissions for Zizmor. Approved by two reviewers with all checks passing. The change adds a single permission line to align with official documentation.
83%
#416 ci: update permissions for zizmor craft-store merged Merged following two reviewer approvals. Updated CI workflow permissions for the zizmor security tool. All required checks passed, and the four-line configuration change was integrated into the main branch.
83%
#151 ci: add zizmor workflow starflow merged Merged a Zizmor workflow to automate CI security checks. Approved by two reviewers with all CI checks passing. The single 15-line change integrates automated security scanning into the repository pipeline.
78%
#1156 ci: add zizmor workflow craft-application merged Merged the addition of the zizmor CI workflow for security scanning. Approved by two reviewers with passing checks. The change adds a single workflow file to enable automated analysis.
77%
#1324 ci: update permissions for zimzor rockcraft merged Merged to fix a broken security workflow by updating zimzor permissions. Approved by two reviewers, passed CI checks, and applied a four-line permission adjustment.
76%
#585 fix(ci): resolve all zizmor findings in GitHub workflows starbase merged Merged. Resolved all 44 zizmor findings in GitHub Actions by pinning actions to commit hashes, restricting permissions, removing secrets inheritance, replacing a release action with a script, and adding justified ignores. All CI checks passed.
76%
#208 ci: update permissions for zimzor craft-grammar merged Merged CI permission updates for zimzor, resolving a blockage in the security workflow. Approved by a reviewer, passed all checks, and integrated with a minimal three-line change to a single workflow file.
75%