Skip to content

Commit 8adb304

Browse files
authored
ci: set zizmor min-severity and min-confidence to medium (#620)
Part of apache/iceberg#16000 Gets rid of `zizmor: ignore[cache-poisoning]`, its low confidence. Set `min-severity: medium` and `min-confidence: medium` in `.github/workflows/zizmor.yml` Validated locally: ``` GH_TOKEN=`gh auth token` uvx zizmor --min-severity medium --min-confidence medium .github/ ```
1 parent e7b228b commit 8adb304

2 files changed

Lines changed: 3 additions & 1 deletion

File tree

.github/workflows/test.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -123,7 +123,7 @@ jobs:
123123
run: |
124124
vcpkg install zlib:x64-windows nlohmann-json:x64-windows nanoarrow:x64-windows roaring:x64-windows cpr:x64-windows
125125
- name: Setup sccache
126-
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 # zizmor: ignore[cache-poisoning] -- only used for build caching, no artifacts published
126+
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
127127
- name: Start MinIO
128128
shell: bash
129129
run: bash ci/scripts/start_minio.sh

.github/workflows/zizmor.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,3 +42,5 @@ jobs:
4242
uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2
4343
with:
4444
advanced-security: false
45+
min-severity: medium
46+
min-confidence: medium

0 commit comments

Comments
 (0)