ci: allow zizmor action so the workflow can run
I maintainer di solito rispondono entro 4 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 1/5
- Tempo stimato
- Meno di un'ora
- Idoneità per principianti
- 55/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- github-actions
- Ambito
- ci-cd
Direzione di ricerca
Start with the existing zizmor workflow and verify that its zizmorcore/zizmor-action reference is included in the repository's allowed GitHub Actions. A maintainer with Admin permissions must make the approval change; rerun the workflow afterward, and confirm it starts with jobs instead of ending in startup_failure.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
The zizmor workflow added in #144 is currently failing before any job is created.
Affected runs end with:
startup_failure
and contain no jobs.
This also occurs on #148, which originated from nodejs/learn itself, so the failure is not specific to external pull requests.
Likely cause
nodejs/learn uses an explicit GitHub Actions allowlist. The workflow added in #146 documents that new Actions need to be approved by a maintainer with Admin permissions.
There is a direct precedent in nodejs/nodejs.org#8728: when zizmor was introduced there, maintainers confirmed that the workflow was not starting because zizmorcore/zizmor-action had not yet been added to that repository's Actions allowlist. After it was allowed, the existing zizmor workflow ran successfully.
The Learn workflow currently uses:
uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
Suggested fix
Could a maintainer with Admin permissions verify that zizmorcore/zizmor-action is included in this repository's allowed Actions?
After it is allowed, the existing workflow can be rerun to verify that it starts normally.
cc @nodejs/web-infra
- Lingua principale
- JavaScript
- Stelle
- 32
- Fork
- 173
- Merge medio
- 10g 3h
- PR unite (30g)
- 12
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di nodejs/learn
-
Add an issue templateAperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
I maintainer di solito rispondono entro 4 giorni
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 65/100
nodejs/learn#112 · 1 commento · 1 reazione ·
I maintainer di solito rispondono entro 4 giorni
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
I maintainer di solito rispondono entro 4 giorni
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
I maintainer di solito rispondono entro 4 giorni
-
Add auto-merge workflowAperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
I maintainer di solito rispondono entro 4 giorni
Tutte le issue di nodejs/learn
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 80/100
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
NationalSecurityAgency/skills-service#4052 ·
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
githubnext/gh-aw-workshop#4251 ·
I maintainer di solito rispondono entro 1 giorno
-
customer-support needs-triage Platform(Default)
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
Leonxlnx/taste-skill#129 ·
I maintainer di solito rispondono entro 1 giorno