Skip to content

github-app: test repositories, not repository - #2011

Merged
woodruffw merged 3 commits into
mainfrom
ww/fix-2009
May 15, 2026
Merged

woodruffw merged 3 commits into
mainfrom
ww/fix-2009

Conversation

@woodruffw

@woodruffw woodruffw commented May 15, 2026 •

Copy link
Copy Markdown
Member

Fixes #2008.

@woodruffw woodruffw added the bugfix Fixes a known bug label May 15, 2026
@woodruffw
woodruffw enabled auto-merge (squash) May 15, 2026 15:22
@woodruffw
woodruffw merged commit 506f085 into main May 15, 2026
12 checks passed
@woodruffw
woodruffw deleted the ww/fix-2009 branch May 15, 2026 15:24
emsearcy added a commit to linuxfoundation/lfx-v2-newsletter-service that referenced this pull request Oct 6, 2026
The github-app audit in zizmor v1.25.0 (bundled by MegaLinter v9.6.0)
incorrectly flags this actions/create-github-app-token usage as
granting access to all repositories for the owner's app installation,
even though repositories: lfx-v2-argocd already scopes the minted
token to a single repository. This is a known upstream bug, fixed in
zizmor v1.25.1 and v1.29.0 (zizmorcore/zizmor#2011, #2227); our local
zizmor v1.30.1 confirms zero findings on this file already.

Suppress with an inline ignore comment (same pattern already used in
lfx-v2-argocd's own create-version-bump-pr.yml) until MegaLinter
bumps its bundled zizmor past v1.29.0.

Assisted-by: github-copilot:claude-sonnet-5
Signed-off-by: Eric Searcy <eric@linuxfoundation.org>
emsearcy added a commit to linuxfoundation/lfx-v2-query-service that referenced this pull request Oct 6, 2026
The github-app audit in zizmor v1.25.0 (bundled by MegaLinter v9.6.0)
incorrectly flags this actions/create-github-app-token usage as
granting access to all repositories for the owner's app installation,
even though repositories: lfx-v2-argocd already scopes the minted
token to a single repository. This is a known upstream bug, fixed in
zizmor v1.25.1 and v1.29.0 (zizmorcore/zizmor#2011, #2227); our local
zizmor v1.30.1 confirms zero findings on this file already.

Suppress with an inline ignore comment (same pattern already used in
lfx-v2-argocd's own create-version-bump-pr.yml) until MegaLinter
bumps its bundled zizmor past v1.29.0.

Assisted-by: github-copilot:claude-sonnet-5
Signed-off-by: Eric Searcy <eric@linuxfoundation.org>
emsearcy added a commit to linuxfoundation/lfx-v2-survey-service that referenced this pull request Oct 6, 2026
The github-app audit in zizmor v1.25.0 (bundled by MegaLinter v9.6.0)
incorrectly flags this actions/create-github-app-token usage as
granting access to all repositories for the owner's app installation,
even though repositories: lfx-v2-argocd already scopes the minted
token to a single repository. This is a known upstream bug, fixed in
zizmor v1.25.1 and v1.29.0 (zizmorcore/zizmor#2011, #2227); our local
zizmor v1.30.1 confirms zero findings on this file already.

Suppress with an inline ignore comment (same pattern already used in
lfx-v2-argocd's own create-version-bump-pr.yml) until MegaLinter
bumps its bundled zizmor past v1.29.0.

Assisted-by: github-copilot:claude-sonnet-5
Signed-off-by: Eric Searcy <eric@linuxfoundation.org>
emsearcy added a commit to linuxfoundation/lfx-v2-voting-service that referenced this pull request Oct 6, 2026
The github-app audit in zizmor v1.25.0 (bundled by MegaLinter v9.6.0)
incorrectly flags this actions/create-github-app-token usage as
granting access to all repositories for the owner's app installation,
even though repositories: lfx-v2-argocd already scopes the minted
token to a single repository. This is a known upstream bug, fixed in
zizmor v1.25.1 and v1.29.0 (zizmorcore/zizmor#2011, #2227); our local
zizmor v1.30.1 confirms zero findings on this file already.

Suppress with an inline ignore comment (same pattern already used in
lfx-v2-argocd's own create-version-bump-pr.yml) until MegaLinter
bumps its bundled zizmor past v1.29.0.

Assisted-by: github-copilot:claude-sonnet-5
Signed-off-by: Eric Searcy <eric@linuxfoundation.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Fixes a known bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant