Skip to content

ci: enforce strict zizmor audits and harden workflows / 启用严格 zizmor 审计并加固工作流 - #3161

Merged
adibarra merged 5 commits into
mainfrom
ci/zizmor-strict
Sep 16, 2026
Merged

adibarra merged 5 commits into
mainfrom
ci/zizmor-strict

Conversation

@adibarra

@adibarra adibarra commented Sep 16, 2026 •

Copy link
Copy Markdown
Collaborator

Add Zizmor security auditing and fix the workflow findings it exposes. Native path filters keep Python CI and workflow auditing independent: Python changes run Lint and Tests in parallel; workflow/action/security configuration changes run Zizmor. CI definitions, Ruff/pytest configuration, and MCP dependencies also trigger Python CI. Editing ci.yml runs all three jobs. Each workflow can be dispatched manually.

  • Use the latest Zizmor release at least 12 hours old, with the auditor persona, strict collection, online checks, and no global rule exclusions.
  • Pass workflow inputs as data instead of interpolating them into shell/Python source, and construct ingest dispatch payloads through the GitHub API.
  • Narrow reusable-workflow secrets and token permissions; remove persisted benchmark checkout credentials while retaining the profiling storage deploy key needed to push traces.
  • Combine Claude coding and review workflows, preserving their separate jobs, permissions, and prompts. Scope review concurrency per PR and use the official action's CLI installer.

Inline exceptions cover existing repository-scoped integration secrets, independent GPU/comment/Klaud requests, trusted pull_request_target control workflows, and the profiling storage push. Moving stored secrets into GitHub Environments remains separate work.

Validation:

  • On 372ebc353, Python CI and Workflow security passed: Ruff, Zizmor, 1,558 tests and 171 subtests. The tests took 34.93 seconds. This PR changes ci.yml, so both workflows correctly run.
  • Independent Claude review found no issues on 4fd413336, before the path-filter correction.
  • The CODEOWNER sign-off status passed. No tests or benchmark settings changed relative to main.
  • Same-repository $/ calls are official GitHub syntax, including reusable workflows. They require runner 2.336.0+; the inspected hosted CI log reports 2.337.0. Current actionlint does not understand this syntax.
  • The combined Claude workflow parsed and ran, but its action skipped review because OIDC validation requires the workflow to match main. Its green job is not review evidence. Post-merge execution still needs verification.
  • No local tests or GPU benchmarks were run during takeover.
中文

加入 Zizmor 安全审计,并修复发现的工作流问题。使用 GitHub 原生路径过滤,将 Python CI 与工作流审计独立触发:Python 变更并行运行 Lint 和 Tests;工作流/action/安全配置变更运行 Zizmor。CI 定义、Ruff/pytest 配置和 MCP 依赖变更也会触发 Python CI。修改 ci.yml 会运行全部三项任务。两个工作流均可手动分发。

  • 使用发布至少 12 小时的最新 Zizmor,启用 auditor 模式、严格输入收集和在线检查,不全局禁用规则。
  • 将工作流输入作为数据传递,避免直接插入 Shell/Python 源码;通过 GitHub API 构建 ingest 分发请求。
  • 收紧可复用工作流的 secret 传递和 token 权限,停止在基准测试 checkout 中保留凭据;仅保留向 profiling 存储仓库推送所需的 deploy key。
  • 合并 Claude 编码与审阅工作流,保留各自的任务、权限和提示词;按 PR 隔离审阅并发,并使用官方 action 的 CLI 安装器。

行内豁免涵盖现有仓库级集成 secret、独立的 GPU/评论/Klaud 请求、可信的 pull_request_target 控制工作流,以及 profiling 存储推送。将实际 secret 值迁入 GitHub Environments 留作独立任务。

验证结果:

  • 372ebc353 的 Python CI 和 Workflow security 均通过:Ruff、Zizmor、1,558 项测试与 171 项子测试。测试耗时 34.93 秒。本 PR 修改了 ci.yml,因此两个工作流均按预期运行。
  • 独立 Claude 审阅 已在路径过滤修正前的 4fd413336 上完成,未发现问题。
  • CODEOWNER 签核状态通过。相较 main,本 PR 未修改测试或基准测试配置。
  • 同仓库 $/ 引用属于 GitHub 官方支持的语法,适用于可复用工作流。要求 runner 2.336.0+;已检查的托管 CI 日志显示 2.337.0。当前 actionlint 尚不识别该语法。
  • 合并后的 Claude 工作流 已成功解析并运行,但 action 因 OIDC 校验要求工作流与 main 一致而跳过审阅。绿色任务状态不能作为审阅证据,合并后仍需确认其实际运行。
  • 接手期间未运行本地测试或 GPU 基准测试。

在 CI 中启用严格的 zizmor 审计,修复工作流输入注入、凭据持久化及权限和 secret 传递问题,并记录有意保留的架构豁免。
合并 Claude 编码和审阅工作流并保留独立权限,由官方 action 安装 CLI。移除 npm 安装及锁文件,zizmor 使用发布至少 12 小时的最新版本。

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Beyond the inline finding, I also checked the Slurm cleanup steps in benchmark-tmpl.yml (around line 241) and profile.yml (around line 238) that reference ${RUNNER_NAME} without an explicit step-level env: mapping — RUNNER_NAME is one of GitHub Actions' default runner environment variables, automatically present in every step's shell, so this is not a regression.

Extended reasoning...

I verified the two candidate issues listed as ruled out this run. Both concern the Slurm cleanup steps in benchmark-tmpl.yml and profile.yml, which were changed from using the ${{ runner.name }} GitHub Actions expression to the shell variable ${RUNNER_NAME}, without declaring RUNNER_NAME in that step's env: block. My own check of GitHub Actions' documented default environment variables confirms RUNNER_NAME is automatically exported into every step's process environment (alongside RUNNER_OS, GITHUB_WORKSPACE, etc.), so the shell reference resolves correctly even without an explicit env: entry — the ruled-out conclusion holds. I did not re-litigate the already-confirmed $/-prefix reusable-workflow reference bug, which is inline-commented and independently severe (it appears at ~24 call sites across run-sweep.yml, e2e-tests.yml, and klaud-plan.yml, per my own grep of the diff), and needs the author's attention.

Comment thread .github/workflows/run-sweep.yml
合并 main 的最新签核修复和 H200 配置更新,保留工作流加固改动。
@adibarra
adibarra marked this pull request as draft September 16, 2026 01:53
@adibarra
adibarra marked this pull request as ready for review September 16, 2026 01:54

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

按文件类型分开触发 Python CI 和 Zizmor,保留 Lint 与 Tests 并行运行,并同步中英文测试文档。
仅匹配工作流 YAML 文件,避免 README 等文档变更触发 Zizmor。
@adibarra
adibarra merged commit b05775b into main Sep 16, 2026
6 checks passed
@adibarra
adibarra deleted the ci/zizmor-strict branch September 16, 2026 02:58
@adibarra adibarra mentioned this pull request Sep 16, 2026
52 tasks done
Oseltamivir added a commit that referenced this pull request Sep 28, 2026
…/ 同步 Klaud 文档中的模型、action 版本与 zizmor 说明

- Both Klaud steps run claude-opus-5-5 on pinned Claude Code 2.1.282
  since #3432; the docs still named Opus 5 and Fable 5.1.
- claude-code-action pin is v1.0.234 (9171db3e57d6), not v1.0.218.
- Add the actions/github-script v9.0.0 pin used by klaud-plan.yml.
- The internal workflow call is $/.github/..., changed in #3161.
- --no-ignores zizmor now also reports two adhoc-packages findings
  for the pinned CLI install.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant