chore(workflows): use self-repository syntax for in-repo workflow calls - #76
Conversation
Switch the ci-security wrapper from the `./` workspace-relative form to GitHub's `$/` self-repository syntax, and drop the `zizmor: ignore[self-repository]` suppression that was hiding the finding. The `$/` form resolves against the repository at the commit that is running rather than the runner's workspace, and GitHub counts it as a pinned reference, so in-repo calls satisfy policies that require full-length commit SHAs. Behavior is unchanged; the audit now passes on its own merits instead of being silenced, which means it cannot rot when the audit's reasoning changes. Documents the convention in AGENTS.md alongside the existing pinned-ref guidance for external consumers. https://github.blog/changelog/2026-07-30-reference-same-repository-actions-with-self-repository-syntax/
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe ChangesReusable Workflow Reference
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~2 minutes Change: Other Merge Risk: ⚪ Minimal · up to The security workflow reference resolves to the matching workflow at the running commit, with no call-interface change. It appears ready for GitHub.com; confirm first if GitHub Enterprise Server is a required execution environment, as this syntax is unavailable there. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the workflow call, Comment |
Summary
Switches the
ci-securitywrapper from the./workspace-relative form to GitHub's$/self-repository syntax, and drops thezizmor: ignore[self-repository]suppression that was hiding the finding. Documents the convention inAGENTS.md.Changes
.github/workflows/ci-security.yaml—uses: ./.github/workflows/reusable-ci-security.yamlbecomesuses: $/.github/workflows/reusable-ci-security.yamlAGENTS.md— the in-repo example uses$/, with a short note on whyWhy
A
$/reference resolves against the repository at the commit that is running, rather than the runner's workspace, and GitHub counts it as a pinned reference. That means in-repo calls satisfy policies that require full-length commit SHAs, which the./form does not.Behavior is unchanged. The practical win is that the audit now passes on its own merits instead of being silenced, so the finding cannot rot the next time the audit's reasoning changes. Suppressions in this repository drop from two to one, and the remaining one is unrelated:
adhoc-packagesinreusable-test-build-tools.yaml, where installing a caller-requested package is the workflow's purpose.Reference: Reference same-repository actions with self-repository syntax
Verification
zizmor --min-severity low --min-confidence low .reports no findingsci-securityrun on this PR is itself the testNotes
Independent of the Tailscale workflow work, which is on a separate branch.
Summary by CodeRabbit