Skip to content

ci: fix zizmor findings - #1462

Open
Ron (rjaegers) wants to merge 3 commits into
mainfrom
ci/fix-zizmor-findings
Open

Ron (rjaegers) wants to merge 3 commits into
mainfrom
ci/fix-zizmor-findings

Conversation

@rjaegers

@rjaegers Ron (rjaegers) commented Sep 12, 2026

Copy link
Copy Markdown
Member

🚀 Hey, I have created a Pull Request

Description of changes

This pull request updates several GitHub Actions workflow files to change how reusable workflows are referenced. The main change is replacing relative paths (e.g., ./.github/workflows/...) with a new syntax using a $ prefix (e.g., $/.github/workflows/...). This affects multiple workflows and their job steps, ensuring consistency and possibly preparing for a new workflow resolution mechanism.

Workflow reference updates:

  • Updated calls to reusable workflows in .github/workflows/build-push-test.yml, .github/workflows/continuous-integration.yml, .github/workflows/release-build.yml, .github/workflows/wc-build-push-test.yml, and .github/workflows/wc-build-push.yml to use the `# 🚀 Hey, I have created a Pull Request

Description of changes

prefix instead of the previous relative path syntax. [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12]

No other functional or logic changes are introduced in this pull request.

✔️ Checklist

  • I have followed the contribution guidelines for this repository
  • I have added tests for new behavior, and have not broken any existing tests
  • I have added or updated relevant documentation
  • I have verified that all added components are accounted for in the SBOM
  • I understand the image size delta and agree the functionality justifies it

Copilot AI lite review requested due to automatic review settings September 12, 2026 13:16
@rjaegers
Ron (rjaegers) requested a review from a team as a code owner September 12, 2026 13:16
@rjaegers Ron (rjaegers) changed the title ci: use GitHub Actions self-reference format ci: fix zizmor findings Sep 12, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Critical workflow references are invalid and will prevent the affected workflows from running.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

This PR updates GitHub Actions reusable-workflow references to address zizmor findings.

Changes:

  • Replaced local ./.github/workflows/... references with $/.github/workflows/....
  • Applied changes across five build, CI, test, and release workflows.
File summaries
File Summary
.github/workflows/wc-build-push.yml Contains an invalid reusable-workflow reference.
.github/workflows/wc-build-push-test.yml Contains multiple invalid reusable-workflow references.
.github/workflows/release-build.yml Contains multiple invalid reusable-workflow references.
.github/workflows/continuous-integration.yml Contains multiple invalid reusable-workflow references.
.github/workflows/build-push-test.yml Contains multiple invalid reusable-workflow references.
Review details

Suppressed comments (8)

.github/workflows/build-push-test.yml:57

  • jobs.build-push-test-flavors.uses must use a local reusable-workflow path beginning with ./ (or a fully qualified repository reference with @ref); $/.github/workflows/wc-build-push-test.yml is not a valid GitHub Actions workflow reference, so the flavor matrix job cannot run. Restore the ./.github/... path.
    uses: $/.github/workflows/wc-build-push-test.yml

.github/workflows/continuous-integration.yml:36

  • jobs.dependency-review.uses must use a local reusable-workflow path beginning with ./ (or a fully qualified repository reference with @ref); $/.github/workflows/wc-dependency-review.yml is not a valid GitHub Actions workflow reference, so this CI job will be rejected before it runs. Restore the ./.github/... path.
    uses: $/.github/workflows/wc-dependency-review.yml

.github/workflows/continuous-integration.yml:66

  • jobs.generate-documents.uses must use a local reusable-workflow path beginning with ./ (or a fully qualified repository reference with @ref); $/.github/workflows/wc-document-generation.yml is not a valid GitHub Actions workflow reference, so this CI job will be rejected before it runs. Restore the ./.github/... path.
    uses: $/.github/workflows/wc-document-generation.yml

.github/workflows/release-build.yml:133

  • jobs.publish-devcontainer-templates.uses must use a local reusable-workflow path beginning with ./ (or a fully qualified repository reference with @ref); $/.github/workflows/wc-publish-templates.yml is not a valid GitHub Actions workflow reference, so this release job cannot run. Restore the ./.github/... path.
    uses: $/.github/workflows/wc-publish-templates.yml

.github/workflows/release-build.yml:140

  • jobs.generate-documents.uses must use a local reusable-workflow path beginning with ./ (or a fully qualified repository reference with @ref); $/.github/workflows/wc-document-generation.yml is not a valid GitHub Actions workflow reference, so this release job cannot run. Restore the ./.github/... path.
    uses: $/.github/workflows/wc-document-generation.yml

.github/workflows/wc-build-push-test.yml:161

  • jobs.integration-test-docker.uses must use a local reusable-workflow path beginning with ./ (or a fully qualified repository reference with @ref); $/.github/workflows/wc-integration-test-docker.yml is not a valid GitHub Actions workflow reference, so this integration-test job cannot run. Restore the ./.github/... path.
    uses: $/.github/workflows/wc-integration-test-docker.yml

.github/workflows/wc-build-push-test.yml:178

  • jobs.integration-test-podman.uses must use a local reusable-workflow path beginning with ./ (or a fully qualified repository reference with @ref); $/.github/workflows/wc-integration-test-podman.yml is not a valid GitHub Actions workflow reference, so this integration-test job cannot run. Restore the ./.github/... path.
    uses: $/.github/workflows/wc-integration-test-podman.yml

.github/workflows/wc-build-push-test.yml:188

  • jobs.acceptance-test.uses must use a local reusable-workflow path beginning with ./ (or a fully qualified repository reference with @ref); $/.github/workflows/wc-acceptance-test.yml is not a valid GitHub Actions workflow reference, so this acceptance-test job cannot run. Restore the ./.github/... path.
    uses: $/.github/workflows/wc-acceptance-test.yml
  • Files reviewed: 5/5 changed files
  • Comments generated: 5
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

build-push-test-base:
name: 🍨 base
uses: ./.github/workflows/wc-build-push-test.yml
uses: $/.github/workflows/wc-build-push-test.yml
build-push-test:
name: Build → Push → Test
uses: ./.github/workflows/build-push-test.yml
uses: $/.github/workflows/build-push-test.yml
name: Build → Push → Test
if: ${{ !startsWith(github.ref_name, 'actions/') }}
uses: ./.github/workflows/build-push-test.yml
uses: $/.github/workflows/build-push-test.yml
build-push:
name: 🛠️
uses: ./.github/workflows/wc-build-push.yml
uses: $/.github/workflows/wc-build-push.yml
sanitize-image-name:
name: 🧼
uses: ./.github/workflows/wc-sanitize-image-name.yml
uses: $/.github/workflows/wc-sanitize-image-name.yml
@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-base:edgeghcr.io/philips-software/amp-devcontainer-base:pr-1462

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 87.58 MB 87.58 MB +474 B (+0%) 🔼
linux/arm64 85.15 MB 85.15 MB 92 B (0%) 🔽

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-docs:edgeghcr.io/philips-software/amp-devcontainer-docs:pr-1462

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 219.12 MB 219.12 MB +773 B (+0%) 🔼
linux/arm64 214.83 MB 214.83 MB 61 B (0%) 🔽

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-rust:edgeghcr.io/philips-software/amp-devcontainer-rust:pr-1462

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 443.49 MB 443.49 MB +844 B (+0%) 🔼
linux/arm64 393.02 MB 393.02 MB 199 B (0%) 🔽

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-rust:edgeghcr.io/philips-software/amp-devcontainer-embedded-rust:pr-1462

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 510.24 MB 510.24 MB +573 B (+0%) 🔼
linux/arm64 459.47 MB 459.47 MB +136 B (+0%) 🔼

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:edgeghcr.io/philips-software/amp-devcontainer-cpp:pr-1462

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 407.71 MB 407.71 MB +2.05 kB (+0%) 🔼
linux/arm64 387.76 MB 387.76 MB 192 B (0%) 🔽

@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
❌ ACTION actionlint 23 13 0 0.16s
✅ DOCKERFILE hadolint 4 0 0 0.21s
✅ JSON npm-package-json-lint yes no no 0.33s
✅ JSON prettier 46 8 0 0 0.57s
✅ JSON v8r 46 0 0 13.53s
✅ MARKDOWN markdownlint 13 0 0 0 0.81s
✅ MARKDOWN markdown-table-formatter 13 0 0 0 0.19s
✅ REPOSITORY betterleaks yes no no 0.98s
✅ REPOSITORY checkov yes no no 25.88s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 63.53s
⚠️ REPOSITORY osv-scanner yes 2 no 1.47s
✅ REPOSITORY secretlint yes no no 1.78s
✅ REPOSITORY syft yes no no 2.62s
✅ REPOSITORY trivy yes no no 10.48s
✅ REPOSITORY trivy-sbom yes no no 0.26s
✅ REPOSITORY trufflehog yes no no 2.85s
⚠️ SPELL lychee 118 1 0 9.54s
✅ YAML prettier 36 0 0 0 0.83s
✅ YAML v8r 36 0 0 11.54s
✅ YAML yamllint 36 0 0 1.02s

Detailed Issues

❌ ACTION / actionlint - 13 errors
.github/workflows/build-push-test.yml:21:11: reusable workflow call "$/.github/workflows/wc-build-push-test.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
   |
21 |     uses: $/.github/workflows/wc-build-push-test.yml
   |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/build-push-test.yml:57:11: reusable workflow call "$/.github/workflows/wc-build-push-test.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
   |
57 |     uses: $/.github/workflows/wc-build-push-test.yml
   |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/continuous-integration.yml:18:11: reusable workflow call "$/.github/workflows/build-push-test.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
   |
18 |     uses: $/.github/workflows/build-push-test.yml
   |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/continuous-integration.yml:36:11: reusable workflow call "$/.github/workflows/wc-dependency-review.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
   |
36 |     uses: $/.github/workflows/wc-dependency-review.yml
   |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/continuous-integration.yml:66:11: reusable workflow call "$/.github/workflows/wc-document-generation.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
   |
66 |     uses: $/.github/workflows/wc-document-generation.yml
   |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/release-build.yml:19:11: reusable workflow call "$/.github/workflows/build-push-test.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
   |
19 |     uses: $/.github/workflows/build-push-test.yml
   |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/release-build.yml:133:11: reusable workflow call "$/.github/workflows/wc-publish-templates.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
    |
133 |     uses: $/.github/workflows/wc-publish-templates.yml
    |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/release-build.yml:140:11: reusable workflow call "$/.github/workflows/wc-document-generation.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
    |
140 |     uses: $/.github/workflows/wc-document-generation.yml
    |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/wc-build-push-test.yml:132:11: reusable workflow call "$/.github/workflows/wc-build-push.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
    |
132 |     uses: $/.github/workflows/wc-build-push.yml
    |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/wc-build-push-test.yml:161:11: reusable workflow call "$/.github/workflows/wc-integration-test-docker.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
    |
161 |     uses: $/.github/workflows/wc-integration-test-docker.yml
    |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/wc-build-push-test.yml:178:11: reusable workflow call "$/.github/workflows/wc-integration-test-podman.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
    |
178 |     uses: $/.github/workflows/wc-integration-test-podman.yml
    |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/wc-build-push-test.yml:188:11: reusable workflow call "$/.github/workflows/wc-acceptance-test.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
    |
188 |     uses: $/.github/workflows/wc-acceptance-test.yml
    |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.github/workflows/wc-build-push.yml:67:11: reusable workflow call "$/.github/workflows/wc-sanitize-image-name.yml" at "uses" is not following the format "owner/repo/path/to/workflow.yml@ref" nor "./path/to/workflow.yml". see https://docs.github.com/en/actions/learn-github-actions/reusing-workflows for more details [workflow-call]
   |
67 |     uses: $/.github/workflows/wc-sanitize-image-name.yml
   |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........154
🔗 Unique.........126
✅ Successful.....148
⏳ Timeouts.........0
🔀 Redirected......19
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden

Hint: Followed 19 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 2 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned package-lock.json file and found 73 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned .github/actions/update-vscode-extensions/package-lock.json file and found 288 packages
End status: 83 dirs visited, 280 inodes visited, 9 Extract calls, 36.925651ms elapsed, 36.925832ms wall time

Total 3 packages affected by 4 known vulnerabilities (0 Critical, 2 High, 0 Medium, 0 Low, 2 Unknown) from 2 ecosystems.
2 vulnerabilities can be fixed.

+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| OSV URL                             | CVSS | ECOSYSTEM | PACKAGE               | VERSION | FIXED VERSION | SOURCE                                            |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110   |      | crates.io | bare-metal            | 0.2.5   | --            | test/embedded-rust/workspace/cortex-m/Cargo.lock  |
| https://osv.dev/RUSTSEC-2026-0110   |      | crates.io | bare-metal            | 0.2.5   | --            | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
| https://osv.dev/GHSA-mh99-v99m-4gvg | 7.5  | npm       | brace-expansion (dev) | 5.0.7   | 5.0.8         | package-lock.json                                 |
| https://osv.dev/GHSA-rgw5-rvv9-x895 | 7.5  | npm       | brace-expansion (dev) | 5.0.7   | 5.0.9         | package-lock.json                                 |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@rjaegers

Copy link
Copy Markdown
Member Author

Waiting on rhysd/actionlint#732. Followed by an intake into MegaLinter.

@rjaegers
Ron (rjaegers) deployed to acceptance-testing September 12, 2026 13:37 — with GitHub Actions Active
@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-cpp:edgeghcr.io/philips-software/amp-devcontainer-embedded-cpp:pr-1462

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 609.99 MB 609.99 MB 176 B (0%) 🔽
linux/arm64 589.23 MB 589.23 MB +1.03 kB (+0%) 🔼

@github-actions

Copy link
Copy Markdown
Contributor

Test Results

 25 files  ±0   25 suites  ±0   19m 54s ⏱️ -7s
 48 tests ±0   48 ✅ ±0  0 💤 ±0  0 ❌ ±0 
209 runs  ±0  209 ✅ ±0  0 💤 ±0  0 ❌ ±0 

Results for commit eec7756. ± Comparison against base commit e7fc5ed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants