ci: fix zizmor warnings
Metadata
Current evaluation
Merged after approval by two reviewers. Resolved zizmor CI warnings across two files with minimal changes.
Suggested action: —
No scores available.
Issue body
Fixes zizmor warnings from https://github.com/canonical/snapcraft/pull/6391.
---
- [x] I've followed the [contribution guidelines](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md).
- [x] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/).
- [x] I've successfully run `make lint && make test`.
- [ ] I've added or updated any relevant documentation.
- [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.
- [ ] I've updated the relevant release notes.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged after approval by two reviewers. Resolved zizmor CI warnings across two files with minimal changes. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
5
Complexity:
15
Confidence:
85
|
needs review | Fixes zizmor CI warnings by updating GitHub Actions workflows. Currently approved by one reviewer with two unresolved comments, and several integration tests are failing. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
5
Complexity:
15
Confidence:
90
|
needs review | Updates GitHub Actions workflows to resolve zizmor security lint warnings. All CI checks pass except pending integration tests. Awaiting maintainer review. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
0
Complexity:
5
Confidence:
90
|
needs review | Updates GitHub Actions workflows to resolve zizmor security warnings. Small CI-only change with passing checks and pending integration tests. Currently awaiting maintainer review. |
Update history
| Date | Change |
|---|---|
| updated | |
| updated | |
| updated | |
| created |
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #416 ci: update permissions for zizmor | craft-store | merged | Merged following two reviewer approvals. Updated CI workflow permissions for the zizmor security tool. All required checks passed, and the four-line configuration change was integrated into the main branch. | |
| #426 ci: fix security scanner | imagecraft | merged | Merged a one-line fix for the zizmor security scanner in the CI pipeline. Approved by one reviewer and passed required checks before integration. | |
| #168 ci: update required permissions for zizmor | starflow | merged | Merged CI workflow update adding required permissions for Zizmor. Approved by two reviewers with all checks passing. The change adds a single permission line to align with official documentation. | |
| #1163 ci: add zizmor actions permission | craft-application | merged | Merged a single-line update to grant zizmor actions permissions in the CI configuration. Approved by one reviewer and passed all security scans and tests. | |
| #1675 ci: make zizmor accept unpinned references to Starflow | craft-parts | merged | Updates CI configuration to allow zizmor to accept unpinned references to Starflow. Approved by two reviewers with zero unresolved comments. Minimal change focused on security scanning configuration. | |
| #151 ci: add zizmor workflow | starflow | merged | Merged a Zizmor workflow to automate CI security checks. Approved by two reviewers with all CI checks passing. The single 15-line change integrates automated security scanning into the repository pipeline. | |
| #167 ci: remove deprecated flag for zimzor | starflow | merged | Merged removal of the deprecated upload-sarif flag from zizmor CI configuration. This resolves recurring CI warnings by relying on default SARIF upload behavior. Approved by one reviewer with all checks passing. | |
| #1324 ci: update permissions for zimzor | rockcraft | merged | Merged to fix a broken security workflow by updating zimzor permissions. Approved by two reviewers, passed CI checks, and applied a four-line permission adjustment. | |
| #1156 ci: add zizmor workflow | craft-application | merged | Merged the addition of the zizmor CI workflow for security scanning. Approved by two reviewers with passing checks. The change adds a single workflow file to enable automated analysis. | |
| #471 ci: update permissions for zimzor | craft-cli | merged | Merged update to CI permissions for zimzor, resolving a security workflow execution failure. Approved by one reviewer and passed all continuous integration checks. |