ci: add zizmor actions permission
Metadata
Current evaluation
Merged after approval by two reviewers. Adds required GitHub Actions permissions for the zizmor security scanner to enable CI checks. The change is minimal, modifying a single file with one line addition.
Suggested action: —
No scores available.
Issue body
- [ ] Have you followed the guidelines for contributing?
- [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `make lint && make test`?
- [ ] Have you added an entry to the changelog (`docs/reference/changelog.rst`)?
---
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged after approval by two reviewers. Adds required GitHub Actions permissions for the zizmor security scanner to enable CI checks. The change is minimal, modifying a single file with one line addition. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
5
Complexity:
5
Confidence:
95
|
needs review | Adds zizmor GitHub Actions permission to CI configuration. Approved by one reviewer, CI checks are passing or pending, and the change is minimal (+1/-0 lines). | |
| qwen/qwen3.6-35b-a3b |
Staleness:
5
Complexity:
5
Confidence:
95
|
needs review | Adds zizmor Actions permission to CI workflow. All checks passing, approved by one reviewer, ready to merge. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
5
Complexity:
5
Confidence:
90
|
needs review | Adds zizmor GitHub Actions permission to CI workflow. PR is fresh, all CI checks pass, awaiting maintainer review. |
Update history
| Date | Change |
|---|---|
| updated | |
| updated | |
| created |
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #591 ci: add zizmor actions permission | starbase | merged | Merged to update GitHub Actions permissions for the zizmor security scanner. Approved by one reviewer with all CI checks passing. | |
| #251 ci: update permissions for zizmor | craft-archives | merged | Merged after approval and passing CI checks. Updated GitHub Actions permissions for the zizmor security scanner with a single-line configuration change. | |
| #1163 ci: add zizmor actions permission | craft-application | merged | Merged a single-line update to grant zizmor actions permissions in the CI configuration. Approved by one reviewer and passed all security scans and tests. | |
| #168 ci: update required permissions for zizmor | starflow | merged | Merged CI workflow update adding required permissions for Zizmor. Approved by two reviewers with all checks passing. The change adds a single permission line to align with official documentation. | |
| #416 ci: update permissions for zizmor | craft-store | merged | Merged following two reviewer approvals. Updated CI workflow permissions for the zizmor security tool. All required checks passed, and the four-line configuration change was integrated into the main branch. | |
| #151 ci: add zizmor workflow | starflow | merged | Merged a Zizmor workflow to automate CI security checks. Approved by two reviewers with all CI checks passing. The single 15-line change integrates automated security scanning into the repository pipeline. | |
| #1156 ci: add zizmor workflow | craft-application | merged | Merged the addition of the zizmor CI workflow for security scanning. Approved by two reviewers with passing checks. The change adds a single workflow file to enable automated analysis. | |
| #1324 ci: update permissions for zimzor | rockcraft | merged | Merged to fix a broken security workflow by updating zimzor permissions. Approved by two reviewers, passed CI checks, and applied a four-line permission adjustment. | |
| #585 fix(ci): resolve all zizmor findings in GitHub workflows | starbase | merged | Merged. Resolved all 44 zizmor findings in GitHub Actions by pinning actions to commit hashes, restricting permissions, removing secrets inheritance, replacing a release action with a script, and adding justified ignores. All CI checks passed. | |
| #208 ci: update permissions for zimzor | craft-grammar | merged | Merged CI permission updates for zimzor, resolving a blockage in the security workflow. Approved by a reviewer, passed all checks, and integrated with a minimal three-line change to a single workflow file. |