Skip to content

Initial workflows static analysis fixes#39097

Open
derrickaw wants to merge 3 commits into
masterfrom
20260624_zizmorInitial
Open

Initial workflows static analysis fixes#39097
derrickaw wants to merge 3 commits into
masterfrom
20260624_zizmorInitial

Conversation

@derrickaw

@derrickaw derrickaw commented Jun 25, 2026

Copy link
Copy Markdown
Collaborator
  1. Static analysis on workflows
  2. zizmor --fix=all --gh-token=$(gh auth token) .github/workflows/
  3. Added an ignore rule for commit sha.
  4. Other findings will need to be investigated more in another PR.
  5. First part of [Task]: Remove Zizmor workflow vulnerability findings #39105

Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:

  • Mention the appropriate issue in your description (for example: addresses #123), if applicable. This will automatically add a link to the pull request in the issue. If you would like the issue to automatically close on merging the pull request, comment fixes #<ISSUE NUMBER> instead.
  • Update CHANGES.md with noteworthy changes.
  • If this contribution is large, please file an Apache Individual Contributor License Agreement.

See the Contributor Guide for more tips on how to make review process smoother.

To check the build health, please visit https://github.com/apache/beam/blob/master/.test-infra/BUILD_STATUS.md

GitHub Actions Tests Status (on master branch)

Build python source distribution and wheels
Python tests
Java tests
Go tests

See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.

@github-actions github-actions Bot added the build label Jun 25, 2026
Comment thread .github/workflows/deploy_release_candidate_pypi.yaml Dismissed
Comment thread .github/workflows/git_tag_released_version.yml Dismissed
@derrickaw derrickaw marked this pull request as ready for review June 25, 2026 02:48
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@derrickaw

Copy link
Copy Markdown
Collaborator Author

assign set of reviewers

@github-actions

Copy link
Copy Markdown
Contributor

Assigning reviewers:

R: @Abacn for label build.

Note: If you would like to opt out of this review, comment assign to next reviewer.

Available commands:

  • stop reviewer notifications - opt out of the automated review tooling
  • remind me after tests pass - tag the comment author after tests pass
  • waiting on author - shift the attention set back to the author (any comment or push by the author will return the attention set to the reviewers)

The PR bot will only process comments in the main thread (not review comments).

@derrickaw derrickaw changed the title Initial zizmor Initial workflows static analysis fixes Jun 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants