Repository navigation
Onboard slang-rhi to slang PR board-sync workflow - #804
Conversation
Replace the open-only add-pr-to-project workflow with thin callers for slang's reusable pr-board-sync, wired to this repo's ci and pre-commit gating workflows.
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughChangesThe PR removes the project-classification workflow and adds event-specific workflows for pull-request board synchronization. It handles pull-request events, workflow completion, commit statuses, fork-originated reviews, and scheduled sweeps. Pull-request board synchronization
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: ae5cd31f-66d7-4156-9e27-c3291fd28ae8
📒 Files selected for processing (6)
.github/workflows/add-pr-to-project.yml.github/workflows/pr-checks-complete.yml.github/workflows/pr-commit-status.yml.github/workflows/pr-maintenance.yml.github/workflows/pr-review-fork-apply.yml.github/workflows/pr-review-fork-bridge.yml
💤 Files with no reviewable changes (1)
- .github/workflows/add-pr-to-project.yml
Keep @master callers intentional so board-sync updates propagate without SHA pin-bump PRs; silence CodeRabbit/zizmor unpinned-uses on those refs.
owner/repo alone does not match uses with a subpath; use shader-slang/slang/* so @master board-sync callers are ref-pin allowed.
| actions/*: ref-pin | ||
| github/*: ref-pin | ||
| dependabot/*: ref-pin |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
rg -n \
--glob '.github/workflows/*.yml' \
--glob '.github/workflows/*.yaml' \
'^[[:space:]]*uses:[[:space:]]*(actions|github|dependabot)/' .Repository: shader-slang/slang-rhi
Length of output: 160
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf 'Tracked files under .github:\n'
git ls-files .github | sed -n '1,160p'
printf '\n.zizmor.yml contents:\n'
if [ -f .github/zizmor.yml ]; then
cat -n .github/zizmor.yml
fi
printf '\nWorkflow uses directives (all matching owner prefixes):\n'
rg -n --glob '.github/workflows/*.yml' --glob '.github/workflows/*.yaml' '^[[:space:]]*uses:' .github/workflows || true
printf '\nAll workflow files:\n'
find .github/workflows -maxdepth 1 -type f 2>/dev/null | sort || trueRepository: shader-slang/slang-rhi
Length of output: 3092
🌐 Web query:
zizmor unpinned-uses ref-pin github-actions owner/repo/* pattern reusable workflows
💡 Result:
In zizmor, the unpinned-uses audit is a security check that detects actions or reusable workflows referenced by tag, branch, or other mutable references rather than immutable commit SHA hashes [1][2]. To configure specific patterns for reusable workflows or actions, you use the rules.unpinned-uses.config.policies configuration in your zizmor configuration file [1]. This allows you to apply different pinning policies (such as ref-pin or hash-pin) based on repository patterns [1]. Configuration Details: - The configuration uses a pattern: policy mapping [1]. - Repository patterns allow you to target specific scopes, such as owner/repo/, to apply custom rules [1]. - Valid policies include: - hash-pin: Requires pinning to an immutable commit SHA (the modern default) [1]. - ref-pin: Allows pinning by branch or tag [1]. - any: Requires no specific pinning [1]. Example Configuration: If you wish to allow ref-pinning (branch or tag) for your own organization's reusable workflows (e.g., github/), you can define the following in your configuration [2]: rules: unpinned-uses: config: policies: github/: ref-pin Important Notes: - Scope: The unpinned-uses audit applies to both standard actions and reusable workflows [3][2]. - Default Behavior: As of zizmor v1.20.0, the default policy for all actions and reusable workflows is to require hash-pinning [1][4]. - Pattern Matching: You can use patterns like owner/repo/ to match entire repositories or namespaces [1]. The zizmor documentation provides specific repository pattern formats to ensure precise matching [1][5].
Citations:
- 1: https://docs.zizmor.sh/audits/
- 2: https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md
- 3: Evaluate unpinned reusable workflows at the job level zizmorcore/zizmor#1509
- 4: https://mattsch.com/blog/2026/03/28/harden-your-github-actions-workflows-with-zizmor-dependency-pinning-and-dependency-cooldowns/
- 5: https://github.com/zizmorcore/zizmor/blob/563b7b25/crates/zizmor/src/audit/unpinned_uses.rs
Remove the broad ref-pin exceptions.
The workflow references do not require actions/*, github/*, or dependabot/* ref-pinning: only github/* is needed for the board-sync reusable workflow, and that pattern is already covered by shader-slang/slang/*. Keep hash-pin as the default for all unlisted uses.
Schedule mode:sweep via slang's reusable pr-board-sync so this repo's open PRs get the same nightly backstop as slang.
Summary
add-pr-to-project.ymlworkflow with thin callers for slang's reusablepr-board-sync.yml(Status, Source, assignment, fork-review relay).pr-checks-complete.ymlto slang-rhi's gating Actions workflows (ci,pre-commit).pr-sweep-nightly.ymlso this repo gets its own nightlymode: sweepbackstop (enumerates this caller's open PRs viacontext.repo).SLANG_PR_BOT_TOKENandpermissions: {}per the slang onboarding templates.Companions: shader-slang/slangpy#1084, shader-slang/slangpy-samples#57
Test plan
SLANG_PR_BOT_TOKENis available toshader-slang/slang-rhimain, open a test PR (or use an existing one) and verify it appears on the Slang PR Tracking board with Source/Statusciorpre-commitand confirm Status moves to Snagged (and recovers on green)PR Board Sweep (nightly)viaworkflow_dispatchand confirm open PRs reconcileAdd PR to Project Boardworkflow no longer runs