Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

ci: allow zizmor action so the workflow can run

未关闭
#153 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 4 天内回复

还没有人认领这个 Issue。

评估

难度
1/5
预计耗时
1 小时以内
新手友好度
55/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
github-actions
领域
ci-cd

调研方向

Start with the existing zizmor workflow and verify that its zizmorcore/zizmor-action reference is included in the repository's allowed GitHub Actions. A maintainer with Admin permissions must make the approval change; rerun the workflow afterward, and confirm it starts with jobs instead of ending in startup_failure.

由索引模型根据 Issue 内容生成。

描述

Description

The zizmor workflow added in #144 is currently failing before any job is created.

Affected runs end with:

startup_failure

and contain no jobs.

This also occurs on #148, which originated from nodejs/learn itself, so the failure is not specific to external pull requests.

Likely cause

nodejs/learn uses an explicit GitHub Actions allowlist. The workflow added in #146 documents that new Actions need to be approved by a maintainer with Admin permissions.

There is a direct precedent in nodejs/nodejs.org#8728: when zizmor was introduced there, maintainers confirmed that the workflow was not starting because zizmorcore/zizmor-action had not yet been added to that repository's Actions allowlist. After it was allowed, the existing zizmor workflow ran successfully.

The Learn workflow currently uses:

uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2

Suggested fix

Could a maintainer with Admin permissions verify that zizmorcore/zizmor-action is included in this repository's allowed Actions?

After it is allowed, the existing workflow can be rerun to verify that it starts normally.

cc @nodejs/web-infra

主要语言
JavaScript
星标
32
派生
173
平均合并
10 天 3 小时
30 天内合并 PR
12

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

nodejs/learn 的其他 Issue

查看 nodejs/learn 的全部 Issue

相似的 Issue

更多 JavaScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。