Add zizmor pre-commit configuration
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 45/100
調査の方向性
.github 配下にある既存の GitHub Actions 設定を調査し、続いて参照されている変更 beeware/.github#378 と例 .github/zizmor.yml を確認します。pre-commit パイプラインに zizmor を追加し、Actions 設定に対して実行して、報告された問題をすべて解決します。その際、beeware/.github の参照は @main のままにし、必要な除外については core team とともに文書化します。
索引モデルが issue の本文から書いたものです。
説明
What is the problem or limitation you are having?
zizmor is a useful tool for performing a static analysis of GitHub actions configurations, auditing for common security issues and related problems. It can be run standalone, but it can also be integrated into pre-commit.
Describe the solution you'd like
We should add zizmor to this project's pre-commit pipeline.
This will require fixing any issues that zizmor identifies with the existing Github actions configuration. Zizmor is able to automatically fix many problem, and it is able to make suggestions about other fixes. However, there are some problems where investigation and a manual fix will be required.
Zimor was recently added to the .github repository (see beeware/.github#378). That pull request may be instructive for how to add a zizmor configuration, the types of problems that Zizmor reports, and the fixes for those problems. The most invasive fixes are:
unpinned-uses- this requires providing a full hash for a reference to a GitHub Action, rather than just a version number. These hashes must be manually determined. This must be done for all action reference, except for references tobeeware/.githubactions; see details below.template-injection- Use of${{ }}syntax is a possible vector for security issues because the content isn't escaped; instead of using direct variable substitution, it is necessary to proxy GitHub variables through environment variables.
However, zizmor may find other problems; they should all be resolved.
References to beeware/.github
References to beeware/.github actions are the only actions that are allowed to remain unpinned. As these actions are in the BeeWare repository, the security exposure is different - someone who already has enough access to tamper with those actions likely has access to tamper with other repositories directly.
Any reference to a beeware/.github action should be retained as a reference to @main. A zizmor configuration like this one can be used to silence the zizmor error about unpinned uses.
Describe alternatives you've considered
No real alternative.
Additional context
Skipping rules, excluding files, or raising the minimum report level should not be considered unless absolutely necessary. A member of the core team can advise if you believe you have found a situation that requires an exclusion of this kind; post a comment on this ticket, or ask on Discord if you believe a rule cannot be satisfied.
- 主要言語
- Python
- スター
- 7
- フォーク
- 8
- 平均マージ
- 9時間 41分
- マージ済み PR(30日)
- 1
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
beeware/Python-support-testbed のほかの issue
-
Add cooldown to dependabot actions対応中かも @skritosss が 2 日前に担当しました。 オープンenhancement good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
-
enhancement good first issue
難易度 3/5 1〜2日 初心者へのやさしさ 42/100
beeware/Python-support-testbed#123 · コメント 1 件 ·
beeware/Python-support-testbed の issue をすべて見る
似ている issue
-
feature:LinkChecker
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
digitalfabrik/integreat-cms#4594 ·
メンテナーはふだん 5 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
EleutherAI/lm-evaluation-harness#4319 ·
メンテナーはふだん 1 日以内に返信
-
needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
json_params_matcher fails on falsy top-level JSON primitives (0, False, "")対応中かも @mayureshsonawane17 が今日担当しました。 オープンWaiting for: Product Owner
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 5 日以内に返信