Skip to content

Address https://docs.zizmor.sh/audits/#artipacked findings. - #3081

Merged
eamonnmcmanus merged 1 commit into
mainfrom
ziz
Aug 11, 2026
Merged

eamonnmcmanus merged 1 commit into
mainfrom
ziz

Conversation

@cpovirk

@cpovirk cpovirk commented Aug 3, 2026

Copy link
Copy Markdown
Member

Google has been rolling out zizmor to more of its repos, and zizmor wants persist-credentials: false.

(Gemini leads me to believe that the risk without persist-credentials: false has been minimal since version 6 (actions/checkout#2286?). I haven't tried to verify that. It doesn't seem like the default persist-credentials value is likely to change.)

zizmor also wants us to pin google/oss-fuzz. I posted google/oss-fuzz#6836 (comment).

Purpose

Description

Checklist

  • New code follows the Google Java Style Guide
    This is automatically checked by mvn verify, but can also be checked on its own using mvn spotless:check.
    Style violations can be fixed using mvn spotless:apply; this can be done in a separate commit to verify that it did not cause undesired changes.
  • If necessary, new public API validates arguments, for example rejects null
  • New public API has Javadoc
    • Javadoc uses @since $next-version$
      ($next-version$ is a special placeholder which is automatically replaced during release)
  • If necessary, new unit tests have been added
    • Assertions in unit tests use Truth, see existing tests
    • No JUnit 3 features are used (such as extending class TestCase)
    • If this pull request fixes a bug, a new test was added for a situation which failed previously and is now fixed
  • mvn clean verify javadoc:jar passes without errors

Google has been rolling out `zizmor` to more of its repos, and `zizmor` wants `persist-credentials: false`.

(Gemini leads me to believe that the risk without `persist-credentials: false` has been minimal since [version 6](https://github.com/actions/checkout/releases/tag/v6.0.0) (actions/checkout#2286?). I haven't tried to verify that. It [doesn't seem like the default `persist-credentials` value is likely to change](actions/checkout#485).)

`zizmor` also wants us to pin `google/oss-fuzz`. I posted google/oss-fuzz#6836 (comment).
@eamonnmcmanus
eamonnmcmanus merged commit 119818b into main Aug 11, 2026
30 checks passed
@eamonnmcmanus
eamonnmcmanus deleted the ziz branch August 11, 2026 22:36
@Marcono1234

Marcono1234 commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

zizmor also wants us to pin google/oss-fuzz. I posted google/oss-fuzz#6836 (comment)

It doesn't look like the situation with oss-fuzz will change any time soon, and pinning to an arbitrary commit might prevent Dependabot from updating the commit ref (see comments on the oss-fuzz issue).
The workflow using it is dedicated to just running oss-fuzz and has quite minimal permissions, so maybe adding a suppression comment is fine?

The current approach of just not updating the cifuzz.yml workflow at all (see also commits of #3107) seems problematic in the long run.

Edit: Have created #3135 now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants