ci: add zizmor actions permission
Metadata
Current evaluation
Merged to update GitHub Actions permissions for the zizmor security scanner. Approved by one reviewer with all CI checks passing.
Suggested action: —
No scores available.
Issue body
Updates permissions for zizmor.
---
- [ ] I've followed the [contribution guidelines](https://github.com/canonical/starbase/blob/main/CONTRIBUTING.md).
- [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/).
- [ ] I've successfully run `make lint && make test`.
- [ ] I've added or updated any relevant documentation.
- [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.
- [ ] I've updated the relevant release notes.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged to update GitHub Actions permissions for the zizmor security scanner. Approved by one reviewer with all CI checks passing. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
0
Complexity:
5
Confidence:
95
|
needs review | Updates zizmor GitHub Actions permissions. All CI checks pass. Awaiting maintainer review. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
0
Complexity:
2
Confidence:
95
|
needs review | Updates GitHub Actions permissions for the zizmor security scanner. CI tests pass, policy checks pending, awaiting maintainer review. |
Update history
| Date | Change |
|---|---|
| updated | |
| updated | |
| created |
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #1670 ci: add zizmor actions permission | craft-parts | merged | Merged after approval by two reviewers. Adds required GitHub Actions permissions for the zizmor security scanner to enable CI checks. The change is minimal, modifying a single file with one line addition. | |
| #251 ci: update permissions for zizmor | craft-archives | merged | Merged after approval and passing CI checks. Updated GitHub Actions permissions for the zizmor security scanner with a single-line configuration change. | |
| #1163 ci: add zizmor actions permission | craft-application | merged | Merged a single-line update to grant zizmor actions permissions in the CI configuration. Approved by one reviewer and passed all security scans and tests. | |
| #416 ci: update permissions for zizmor | craft-store | merged | Merged following two reviewer approvals. Updated CI workflow permissions for the zizmor security tool. All required checks passed, and the four-line configuration change was integrated into the main branch. | |
| #168 ci: update required permissions for zizmor | starflow | merged | Merged CI workflow update adding required permissions for Zizmor. Approved by two reviewers with all checks passing. The change adds a single permission line to align with official documentation. | |
| #471 ci: update permissions for zimzor | craft-cli | merged | Merged update to CI permissions for zimzor, resolving a security workflow execution failure. Approved by one reviewer and passed all continuous integration checks. | |
| #245 ci: update permissions for zimzor | craft-archives | merged | Merged update to CI permissions for zimzor, resolving a security workflow execution blockage. Approved by a reviewer and passed all CI checks. | |
| #1324 ci: update permissions for zimzor | rockcraft | merged | Merged to fix a broken security workflow by updating zimzor permissions. Approved by two reviewers, passed CI checks, and applied a four-line permission adjustment. | |
| #151 ci: add zizmor workflow | starflow | merged | Merged a Zizmor workflow to automate CI security checks. Approved by two reviewers with all CI checks passing. The single 15-line change integrates automated security scanning into the repository pipeline. | |
| #585 fix(ci): resolve all zizmor findings in GitHub workflows | starbase | merged | Merged. Resolved all 44 zizmor findings in GitHub Actions by pinning actions to commit hashes, restricting permissions, removing secrets inheritance, replacing a release action with a script, and adding justified ignores. All CI checks passed. |