Skip to content

☔ [gha] pin slsa-github-generator and add yaml header line for zizmor#304

Merged
chicks-net merged 1 commit into
mainfrom
chicks/2026-06-10-zizmor-fixes
Jun 10, 2026
Merged

☔ [gha] pin slsa-github-generator and add yaml header line for zizmor#304
chicks-net merged 1 commit into
mainfrom
chicks/2026-06-10-zizmor-fixes

Conversation

@chicks-net

Copy link
Copy Markdown
Member

Done

  • ☔ [gha] pin slsa-github-generator and add yaml header line for zizmor

Meta

(Automated in .just/gh-process.just.)

Signed-off-by: Christopher Hicks <chicks.net@gmail.com>
Copilot AI review requested due to automatic review settings June 10, 2026 13:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates GitHub automation configuration to satisfy supply-chain tooling requirements by (1) adding an explicit YAML document header for zizmor parsing and (2) pinning the SLSA reusable workflow reference to an immutable commit SHA.

Changes:

  • Add --- YAML document start marker to .github/zizmor.yml.
  • Pin slsa-framework/slsa-github-generator reusable workflow in the release workflow to a full commit SHA (with the corresponding version noted in a comment).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
.github/zizmor.yml Adds a YAML document header to improve/ensure tooling compatibility (zizmor).
.github/workflows/release.yml Replaces a version tag with a commit-SHA pin for the SLSA provenance generator reusable workflow.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@chicks-net chicks-net merged commit e8baae8 into main Jun 10, 2026
27 of 31 checks passed
@chicks-net chicks-net deleted the chicks/2026-06-10-zizmor-fixes branch June 10, 2026 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants