ci: fix security scan workflow
Metadata
Current evaluation
Merged after two approvals. Added security-events write permission to the policy job, resolving the zizmor CI security scan failure. Changes replicate prior updates without modifying dependencies.
Suggested action: —
No scores available.
Issue body
Replicating changes from https://github.com/canonical/craft-archives/pull/245 to fix zizmor CI by adding security-events: write permission to policy job.
This does not actually update the dependencies.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged after two approvals. Added security-events write permission to the policy job, resolving the zizmor CI security scan failure. Changes replicate prior updates without modifying dependencies. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
5
Complexity:
5
Confidence:
85
|
needs review | Adds security-events write permission to the policy job to fix the zizmor CI workflow. Approved by one reviewer, with two CI checks currently failing. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
5
Complexity:
5
Confidence:
85
|
needs review | Adds security-events write permission to the policy job to fix the zizmor CI workflow. Currently awaiting maintainer review with most CI checks passing. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
0
Complexity:
5
Confidence:
90
|
needs review | Adds security-events: write permission to the policy job to fix the zizmor CI workflow. Currently pending maintainer review with one failing OSV-scanner check and other checks passing. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
5
Complexity:
5
Confidence:
90
|
needs review | Adds security-events: write permission to the policy job to fix zizmor CI. Currently pending maintainer review with minor failing CI checks on PR title and OSV-scanner. |
Update history
| Date | Change |
|---|---|
| updated | |
| updated | |
| updated | |
| updated | |
| created |
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #716 ci: add security scan workflow | rockcraft | merged | Merged to add a CI security scan workflow. Approved by two reviewers, the change modifies three files to automate security checks in the pipeline. | |
| #128 ci: add security scan workflow | craft-archives | merged | Merged a change adding a security scan workflow to the CI pipeline. Approved by two reviewers, the update adds 15 lines across one file to automate security checks. | |
| #426 ci: fix security scanner | imagecraft | merged | Merged a one-line fix for the zizmor security scanner in the CI pipeline. Approved by one reviewer and passed required checks before integration. | |
| #276 ci: add security scan workflow | craft-cli | merged | Merged addition of a CI security scan workflow. Approved by two reviewers, the change introduces a new workflow file to automate security checks. | |
| #56 ci: add security scanning workflow | craft-grammar | merged | Merged adds a CI workflow for security scanning. Approved by two reviewers, the change introduces a single configuration file to automate pipeline security checks. | |
| #218 ci: add security scan workflow | craft-store | merged | Merged to add a CI security scan workflow. Approved by two reviewers, the change introduces thirteen lines across one file to automate pipeline security checks. | |
| #494 ci: add security scanning job | craft-application | merged | Merged changes adding a CI security scanning job. Approved by two reviewers, the update introduces 15 lines to one file to automate pipeline security checks. | |
| #1156 ci: add zizmor workflow | craft-application | merged | Merged the addition of the zizmor CI workflow for security scanning. Approved by two reviewers with passing checks. The change adds a single workflow file to enable automated analysis. | |
| #259 ci: add security scan workflow | starbase | merged | Merged to add a CI security scan workflow. Approved by two reviewers, the change introduces a single workflow configuration file with 13 lines to automate security scanning. | |
| #151 ci: add zizmor workflow | starflow | merged | Merged a Zizmor workflow to automate CI security checks. Approved by two reviewers with all CI checks passing. The single 15-line change integrates automated security scanning into the repository pipeline. |