Skip to content

Conversation

@rjaegers
Copy link
Member

@rjaegers rjaegers commented Jun 18, 2025

🚀 Hey, I have created a Pull Request

Description of changes

This PR extends the linter workflow with the zizmor 🌈 linter. Additionally, it implements the suggested improvements.

✔️ Checklist

  • I have followed the contribution guidelines for this repository
  • I have added tests for new behavior, and have not broken any existing tests
  • I have added or updated relevant documentation
  • I have verified that all added components are accounted for in the SBOM

Copilot AI review requested due to automatic review settings June 18, 2025 18:58
@rjaegers rjaegers requested a review from a team as a code owner June 18, 2025 18:58
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds the zizmor linter to the GitHub Actions workflow to help better scrutinize GitHub Actions.

  • Introduces a new job step to run the zizmor linter via a pinned commit.
  • Complements the existing MegaLinter configuration in the workflow.
Comments suppressed due to low confidence (1)

.github/workflows/linting-formatting.yml:31

  • [nitpick] Consider adding a brief comment explaining the purpose of the zizmor linter integration, similar to the comment provided for the oxsecurity MegaLinter entry. This clarification can help future maintainers understand its role in the workflow.
      - uses: zizmorcore/zizmor-action@f52a838cfabf134edcbaa7c8b3677dde20045018 # v0.1.1

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@github-actions
Copy link
Contributor

github-actions bot commented Jun 18, 2025

📦 Container Size Analysis

Comparing ghcr.io/philips-software/amp-devcontainer-rust:edge to ghcr.io/philips-software/amp-devcontainer-rust:pr-830

📈 Size Comparison Table

OS/Platform Previous Size Current Size Change Trend
linux/amd64 481.27M 481.27M 0.00 (+0.00%) 🔄
linux/arm64 432.74M 432.74M 0.00 (+0.00%) 🔄

@github-actions
Copy link
Contributor

github-actions bot commented Jun 18, 2025

🦙 MegaLinter status: ⚠️ WARNING

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 18 0 0 0.5s
✅ DOCKERFILE hadolint 2 0 0 0.9s
✅ GHERKIN gherkin-lint 2 0 0 1.03s
✅ JSON npm-package-json-lint yes no no 0.4s
✅ JSON prettier 16 1 0 0 0.49s
✅ JSON v8r 16 0 0 8.81s
✅ MARKDOWN markdownlint 9 0 0 0 0.89s
✅ MARKDOWN markdown-table-formatter 9 0 0 0 0.25s
✅ REPOSITORY checkov yes no no 16.13s
✅ REPOSITORY gitleaks yes no no 0.4s
✅ REPOSITORY git_diff yes no no 0.01s
⚠️ REPOSITORY grype yes no 2 23.17s
✅ REPOSITORY secretlint yes no no 0.94s
✅ REPOSITORY syft yes no no 1.84s
✅ REPOSITORY trivy yes no no 6.8s
✅ REPOSITORY trivy-sbom yes no no 0.23s
✅ REPOSITORY trufflehog yes no no 3.26s
✅ SPELL lychee 63 0 0 2.43s
✅ YAML prettier 24 0 0 0 0.88s
✅ YAML v8r 24 0 0 5.61s
✅ YAML yamllint 24 0 0 0.72s

See detailed report in MegaLinter reports

MegaLinter is graciously provided by OX Security

@github-actions
Copy link
Contributor

github-actions bot commented Jun 18, 2025

📦 Container Size Analysis

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:edge to ghcr.io/philips-software/amp-devcontainer-cpp:pr-830

📈 Size Comparison Table

OS/Platform Previous Size Current Size Change Trend
linux/amd64 691.26M 691.26M 0.00 (+0.00%) 🔄
linux/arm64 673.40M 673.40M 0.00 (+0.00%) 🔄

@github-actions
Copy link
Contributor

github-actions bot commented Jun 18, 2025

Test Results

 4 files  ±0   4 suites  ±0   2m 29s ⏱️ -1s
31 tests ±0  31 ✅ ±0  0 💤 ±0  0 ❌ ±0 
66 runs  ±0  66 ✅ ±0  0 💤 ±0  0 ❌ ±0 

Results for commit ae05e46. ± Comparison against base commit e0d51f9.

♻️ This comment has been updated with latest results.

@sonarqubecloud
Copy link

@esalman-philips esalman-philips merged commit 9e44a7a into main Jun 19, 2025
34 of 35 checks passed
@esalman-philips esalman-philips deleted the feature/add-zizmor-linter branch June 19, 2025 13:13
@github-actions
Copy link
Contributor

Pull Request Report (#830)

Static measures

Description Value
Number of added lines 95
Number of deleted lines 54
Number of changed files 13
Number of commits 13
Number of reviews 4
Number of comments (w/o review comments) 6
Number of reviews that contains a comment to resolve 3
Number of reviews that requested a change from the author 0
Number of reviews that approved the Pull Request 1
Get the total number of participants of a Pull Request 6

Time related measures

Description Value
PR lead time (from creation to close of PR) 18.3 Hours
Time that was spend on the branch before the PR was created 1.2 Min
Time that was spend on the branch before the PR was merged 18.3 Hours
Time to merge after last review 25 Sec

Status check related measures

Description Value
Total runtime for last status check run (Workflow for PR) 27.5 Min
Total time spend in last status check run on PR 11.1 Min

@github-actions
Copy link
Contributor

🎉 Hooray! The changes in this pull request went live with the release of v6.1.0 🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants