Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Add zizmor pre-commit configuration

Abierto
#191 2 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
45/100
Tipo de issue
Nueva funcionalidad
Claridad
Bastante claro
Estado de actividad
Tranquilo
Stack tecnológico
github-actions
Área
ci-cd, security

Línea de trabajo

Inspecciona la configuración existente de GitHub Actions en .github y, después, revisa el cambio referenciado beeware/.github#378 y el ejemplo .github/zizmor.yml. Añade zizmor al pipeline de pre-commit, ejecútalo contra la configuración de Actions y resuelve todos los problemas notificados, manteniendo las referencias a beeware/.github en @main y documentando cualquier exclusión necesaria con el equipo principal.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

enhancement good first issue

What is the problem or limitation you are having?

zizmor is a useful tool for performing a static analysis of GitHub actions configurations, auditing for common security issues and related problems. It can be run standalone, but it can also be integrated into pre-commit.

Describe the solution you'd like

We should add zizmor to this project's pre-commit pipeline.

This will require fixing any issues that zizmor identifies with the existing Github actions configuration. Zizmor is able to automatically fix many problem, and it is able to make suggestions about other fixes. However, there are some problems where investigation and a manual fix will be required.

Zimor was recently added to the .github repository (see beeware/.github#378). That pull request may be instructive for how to add a zizmor configuration, the types of problems that Zizmor reports, and the fixes for those problems. The most invasive fixes are:

  • unpinned-uses - this requires providing a full hash for a reference to a GitHub Action, rather than just a version number. These hashes must be manually determined. This must be done for all action reference, except for references to beeware/.github actions; see details below.
  • template-injection - Use of ${{ }} syntax is a possible vector for security issues because the content isn't escaped; instead of using direct variable substitution, it is necessary to proxy GitHub variables through environment variables.

However, zizmor may find other problems; they should all be resolved.

References to beeware/.github

References to beeware/.github actions are the only actions that are allowed to remain unpinned. As these actions are in the BeeWare repository, the security exposure is different - someone who already has enough access to tamper with those actions likely has access to tamper with other repositories directly.

Any reference to a beeware/.github action should be retained as a reference to @main. A zizmor configuration like this one can be used to silence the zizmor error about unpinned uses.

Describe alternatives you've considered

No real alternative.

Additional context

Skipping rules, excluding files, or raising the minimum report level should not be considered unless absolutely necessary. A member of the core team can advise if you believe you have found a situation that requires an exclusion of this kind; post a comment on this ticket, or ask on Discord if you believe a rule cannot be satisfied.

Lenguaje dominante
Python
Estrellas
7
Forks
8
Merge medio
9 h 41 min
PR fusionados (30 d)
1

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de beeware/Python-support-testbed

Todos los issues de beeware/Python-support-testbed

Issues similares

Más issues de Python

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.