Skip to content

Fix permissions for Zizmor#74

Merged
Nicolapps merged 1 commit into
mainfrom
nicolas/fix-zizmor-setup
May 22, 2026
Merged

Fix permissions for Zizmor#74
Nicolapps merged 1 commit into
mainfrom
nicolas/fix-zizmor-setup

Conversation

@Nicolapps
Copy link
Copy Markdown
Member


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new Bot commented May 22, 2026

Open in StackBlitz

npm i https://pkg.pr.new/@convex-dev/action-cache@74

commit: 15e4034

@Nicolapps Nicolapps merged commit 67cb4e9 into main May 22, 2026
5 of 6 checks passed
@Nicolapps Nicolapps deleted the nicolas/fix-zizmor-setup branch May 22, 2026 21:24
@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented May 22, 2026

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

The .github/workflows/lint-workflows.yml file is updated to grant the zizmor job write access to security events. A job-scoped permissions block is added under the zizmor job specifying security-events: write, while the workflow-level permissions.contents: read permission remains unchanged. This allows the zizmor job to publish security findings to the repository.

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Description check ❓ Inconclusive The description contains only placeholder text and a contributor agreement with no actual details about the changeset, making it completely uninformative. Add a brief description explaining why the Zizmor job permissions needed to be updated and what security benefit this change provides.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Fix permissions for Zizmor' directly matches the main change: adding security-events write permissions to the Zizmor job in the workflow.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch nicolas/fix-zizmor-setup

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant