Skip to content

Commit 1ad04f9

Browse files
authored
chore: add zizmor config and ignore "unpinned-uses" for plugin-ci-workflows references (#285)
* remove zizmor: ignore unpinned uses directives * add zizmor.yml * chore: restore "ignore unpinned-uses" directive for grafana/plugin-actions * remove .github/zizmor.yml * Revert "chore: restore "ignore unpinned-uses" directive for grafana/plugin-actions" This reverts commit bc3728f.
1 parent 1f78e66 commit 1ad04f9

File tree

6 files changed

+23
-23
lines changed

6 files changed

+23
-23
lines changed

.github/workflows/cd.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -346,7 +346,7 @@ jobs:
346346

347347
ci:
348348
name: CI
349-
uses: grafana/plugin-ci-workflows/.github/workflows/ci.yml@main # zizmor: ignore[unpinned-uses]
349+
uses: grafana/plugin-ci-workflows/.github/workflows/ci.yml@main
350350
needs:
351351
- setup
352352
with:
@@ -563,7 +563,7 @@ jobs:
563563
ENVIRONMENT: ${{ matrix.environment }}
564564

565565
- name: Check and create stub
566-
uses: grafana/plugin-ci-workflows/actions/plugins/publish/check-and-create-stub@main # zizmor: ignore[unpinned-uses]
566+
uses: grafana/plugin-ci-workflows/actions/plugins/publish/check-and-create-stub@main
567567
if: ${{ matrix.environment != 'prod' }}
568568
with:
569569
plugin-id: ${{ fromJSON(needs.ci.outputs.plugin).id }}
@@ -572,13 +572,13 @@ jobs:
572572
gcloud-auth-token: ${{ steps.gcloud.outputs.id_token }}
573573

574574
- name: Check artifact ZIP(s)
575-
uses: grafana/plugin-ci-workflows/actions/plugins/publish/check-artifacts@main # zizmor: ignore[unpinned-uses]
575+
uses: grafana/plugin-ci-workflows/actions/plugins/publish/check-artifacts@main
576576
with:
577577
zips: ${{ needs.upload-to-gcs-release.outputs.gcs-zip-urls }}
578578
plugin-id: ${{ fromJSON(needs.ci.outputs.plugin).id }}
579579

580580
- name: Publish to catalog
581-
uses: grafana/plugin-ci-workflows/actions/plugins/publish/publish@main # zizmor: ignore[unpinned-uses]
581+
uses: grafana/plugin-ci-workflows/actions/plugins/publish/publish@main
582582
with:
583583
zips: ${{ needs.upload-to-gcs-release.outputs.gcs-zip-urls }}
584584
environment: ${{ matrix.environment }}
@@ -883,7 +883,7 @@ jobs:
883883
owner: ${{ github.repository_owner }}
884884

885885
- name: Publish docs
886-
uses: grafana/plugin-ci-workflows/actions/plugins/docs/publish@main # zizmor: ignore[unpinned-uses]
886+
uses: grafana/plugin-ci-workflows/actions/plugins/docs/publish@main
887887
with:
888888
id: ${{ fromJSON(needs.ci.outputs.plugin).id }}
889889
version: ${{ fromJSON(needs.ci.outputs.plugin).version }}
@@ -920,7 +920,7 @@ jobs:
920920

921921
- name: Parse changelog
922922
id: changelog
923-
uses: grafana/plugin-ci-workflows/actions/plugins/changelog@main # zizmor: ignore[unpinned-uses]
923+
uses: grafana/plugin-ci-workflows/actions/plugins/changelog@main
924924
with:
925925
changelog-path: ${{ inputs.plugin-directory }}/CHANGELOG.md
926926

.github/workflows/ci.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -277,7 +277,7 @@ jobs:
277277
return o
278278
279279
- name: Setup
280-
uses: grafana/plugin-ci-workflows/actions/plugins/setup@main # zizmor: ignore[unpinned-uses]
280+
uses: grafana/plugin-ci-workflows/actions/plugins/setup@main
281281
with:
282282
go-version: ${{ inputs.go-version || env.DEFAULT_GO_VERSION }}
283283
node-version: ${{ inputs.node-version || env.DEFAULT_NODE_VERSION }}
@@ -339,7 +339,7 @@ jobs:
339339
working-directory: ${{ inputs.plugin-directory }}
340340

341341
- name: Test and build frontend
342-
uses: grafana/plugin-ci-workflows/actions/plugins/frontend@main # zizmor: ignore[unpinned-uses]
342+
uses: grafana/plugin-ci-workflows/actions/plugins/frontend@main
343343
with:
344344
package-manager: ${{ inputs.package-manager }}
345345
plugin-directory: ${{ inputs.plugin-directory }}
@@ -348,15 +348,15 @@ jobs:
348348

349349
- name: Test and build backend
350350
if: ${{ steps.check-for-backend.outputs.has-backend == 'true' }}
351-
uses: grafana/plugin-ci-workflows/actions/plugins/backend@main # zizmor: ignore[unpinned-uses]
351+
uses: grafana/plugin-ci-workflows/actions/plugins/backend@main
352352
with:
353353
github-token: ${{ steps.generate-github-token.outputs.token }}
354354
plugin-directory: ${{ inputs.plugin-directory }}
355355
secrets: ${{ (fromJson(steps.workflow-context.outputs.result).isTrusted && inputs.backend-secrets != '') && inputs.backend-secrets || '' }}
356356

357357
- name: Package universal ZIP
358358
id: universal-zip
359-
uses: grafana/plugin-ci-workflows/actions/plugins/package@main # zizmor: ignore[unpinned-uses]
359+
uses: grafana/plugin-ci-workflows/actions/plugins/package@main
360360
with:
361361
universal: "true"
362362
dist-folder: dist
@@ -366,7 +366,7 @@ jobs:
366366

367367
- name: Package os/arch ZIPs
368368
id: os-arch-zips
369-
uses: grafana/plugin-ci-workflows/actions/plugins/package@main # zizmor: ignore[unpinned-uses]
369+
uses: grafana/plugin-ci-workflows/actions/plugins/package@main
370370
with:
371371
universal: "false"
372372
dist-folder: dist
@@ -376,7 +376,7 @@ jobs:
376376

377377
- name: Trufflehog secrets scanning
378378
if: ${{ inputs.run-trufflehog == true }}
379-
uses: grafana/plugin-ci-workflows/actions/plugins/trufflehog@main # zizmor: ignore[unpinned-uses]
379+
uses: grafana/plugin-ci-workflows/actions/plugins/trufflehog@main
380380
with:
381381
trufflehog-version: ${{ inputs.trufflehog-version || env.DEFAULT_TRUFFLEHOG_VERSION }}
382382
folder: dist-artifacts
@@ -446,11 +446,11 @@ jobs:
446446
shell: bash
447447

448448
- name: Test docs
449-
uses: grafana/plugin-ci-workflows/actions/plugins/docs/test@main # zizmor: ignore[unpinned-uses]
449+
uses: grafana/plugin-ci-workflows/actions/plugins/docs/test@main
450450

451451
playwright:
452452
name: Playwright E2E tests
453-
uses: grafana/plugin-ci-workflows/.github/workflows/playwright.yml@main # zizmor: ignore[unpinned-uses]
453+
uses: grafana/plugin-ci-workflows/.github/workflows/playwright.yml@main
454454
if: ${{ inputs.run-playwright == true }}
455455
needs:
456456
- test-and-build
@@ -472,7 +472,7 @@ jobs:
472472

473473
playwright-docker:
474474
name: Plugins - Dockerized Playwright E2E tests
475-
uses: grafana/plugin-ci-workflows/.github/workflows/playwright-docker.yml@main # zizmor: ignore[unpinned-uses]
475+
uses: grafana/plugin-ci-workflows/.github/workflows/playwright-docker.yml@main
476476
if: ${{ inputs.run-playwright-docker == true }}
477477
needs:
478478
- test-and-build

.github/workflows/playwright-docker.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@ jobs:
7171

7272
- name: Resolve Grafana E2E versions
7373
id: resolve-versions
74-
uses: grafana/plugin-actions/e2e-version@main # zizmor: ignore[unpinned-uses]
74+
uses: grafana/plugin-actions/e2e-version@main
7575
with:
7676
skip-grafana-dev-image: ${{ inputs.skip-grafana-dev-image }}
7777
version-resolver-type: ${{ inputs.version-resolver-type }}
@@ -136,7 +136,7 @@ jobs:
136136
DOCKER_COMPOSE_FILE: ${{ inputs.grafana-compose-file }}
137137

138138
- name: Wait for Grafana to start
139-
uses: grafana/plugin-actions/wait-for-grafana@main # zizmor: ignore[unpinned-uses]
139+
uses: grafana/plugin-actions/wait-for-grafana@main
140140
with:
141141
url: "${{ inputs.grafana-url }}"
142142

.github/workflows/playwright.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -89,7 +89,7 @@ jobs:
8989

9090
- name: Resolve Grafana E2E versions
9191
id: resolve-versions
92-
uses: grafana/plugin-actions/e2e-version@main # zizmor: ignore[unpinned-uses]
92+
uses: grafana/plugin-actions/e2e-version@main
9393
with:
9494
skip-grafana-dev-image: ${{ inputs.skip-grafana-dev-image }}
9595
version-resolver-type: ${{ inputs.version-resolver-type }}
@@ -222,7 +222,7 @@ jobs:
222222
DOCKER_COMPOSE_FILE: ${{ inputs.docker-compose-file }}
223223

224224
- name: Wait for Grafana to start
225-
uses: grafana/plugin-actions/wait-for-grafana@main # zizmor: ignore[unpinned-uses]
225+
uses: grafana/plugin-actions/wait-for-grafana@main
226226
with:
227227
url: "${{ inputs.grafana-url }}"
228228

.github/workflows/release-please-pr-update-tagged-references.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -121,7 +121,7 @@ jobs:
121121

122122
- name: Switch references
123123
id: switch-references
124-
uses: grafana/plugin-ci-workflows/actions/internal/switch-references@main # zizmor: ignore[unpinned-uses]
124+
uses: grafana/plugin-ci-workflows/actions/internal/switch-references@main
125125
with:
126126
repository: grafana/plugin-ci-workflows
127127
ref: ${{ steps.component-name.outputs.component }}/v${{ steps.get-version.outputs.version }}
@@ -136,7 +136,7 @@ jobs:
136136
- name: Get bot user info
137137
id: get-bot-user
138138
if: steps.switch-references.outputs.changed == 'true'
139-
uses: grafana/plugin-ci-workflows/actions/internal/get-bot-user@main # zizmor: ignore[unpinned-uses]
139+
uses: grafana/plugin-ci-workflows/actions/internal/get-bot-user@main
140140
with:
141141
app-slug: ${{ steps.generate-github-token.outputs.app-slug }}
142142
token: ${{ steps.generate-github-token.outputs.token }}

.github/workflows/release-please-restore-rolling-release.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ jobs:
6767
# (we want to encourage using tagged releases in docs)
6868
- name: Switch references
6969
id: switch-references
70-
uses: grafana/plugin-ci-workflows/actions/internal/switch-references@main # zizmor: ignore[unpinned-uses]
70+
uses: grafana/plugin-ci-workflows/actions/internal/switch-references@main
7171
with:
7272
repository: grafana/plugin-ci-workflows
7373
ref: main
@@ -81,7 +81,7 @@ jobs:
8181
- name: Get bot user info
8282
id: get-bot-user
8383
if: steps.switch-references.outputs.changed == 'true'
84-
uses: grafana/plugin-ci-workflows/actions/internal/get-bot-user@main # zizmor: ignore[unpinned-uses]
84+
uses: grafana/plugin-ci-workflows/actions/internal/get-bot-user@main
8585
with:
8686
app-slug: ${{ steps.generate-github-token.outputs.app-slug }}
8787
token: ${{ steps.generate-github-token.outputs.token }}

0 commit comments

Comments
 (0)