Skip to content

chore(workflows): use self-repository syntax for in-repo workflow calls - #76

Merged
luxass merged 1 commit into
mainfrom
chore/self-repository-syntax
Sep 27, 2026
Merged

luxass merged 1 commit into
mainfrom
chore/self-repository-syntax

Conversation

@luxass

@luxass luxass commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

Switches the ci-security wrapper from the ./ workspace-relative form to GitHub's $/ self-repository syntax, and drops the zizmor: ignore[self-repository] suppression that was hiding the finding. Documents the convention in AGENTS.md.

Changes

  • .github/workflows/ci-security.yaml — uses: ./.github/workflows/reusable-ci-security.yaml becomes uses: $/.github/workflows/reusable-ci-security.yaml
  • AGENTS.md — the in-repo example uses $/, with a short note on why

Why

A $/ reference resolves against the repository at the commit that is running, rather than the runner's workspace, and GitHub counts it as a pinned reference. That means in-repo calls satisfy policies that require full-length commit SHAs, which the ./ form does not.

Behavior is unchanged. The practical win is that the audit now passes on its own merits instead of being silenced, so the finding cannot rot the next time the audit's reasoning changes. Suppressions in this repository drop from two to one, and the remaining one is unrelated: adhoc-packages in reusable-test-build-tools.yaml, where installing a caller-requested package is the workflow's purpose.

Reference: Reference same-repository actions with self-repository syntax

Verification

  • zizmor --min-severity low --min-confidence low . reports no findings
  • The call resolves to the same file, so the ci-security run on this PR is itself the test

Notes

Independent of the Tailscale workflow work, which is on a separate branch.

Summary by CodeRabbit

  • Chores
    • Updated the security workflow configuration to use the repository’s reusable-workflow reference format.
    • Updated repository guidance to describe how reusable workflow references are resolved against the running commit.
    • These changes affect repository workflow configuration and documentation; no end-user product features or behavior are reported as changed.

Switch the ci-security wrapper from the `./` workspace-relative form to
GitHub's `$/` self-repository syntax, and drop the
`zizmor: ignore[self-repository]` suppression that was hiding the finding.

The `$/` form resolves against the repository at the commit that is running
rather than the runner's workspace, and GitHub counts it as a pinned
reference, so in-repo calls satisfy policies that require full-length commit
SHAs. Behavior is unchanged; the audit now passes on its own merits instead of
being silenced, which means it cannot rot when the audit's reasoning changes.

Documents the convention in AGENTS.md alongside the existing pinned-ref
guidance for external consumers.
https://github.blog/changelog/2026-07-30-reference-same-repository-actions-with-self-repository-syntax/
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 7f27bf3b-39ec-4ac3-a2e5-32bbeb30f179

📥 Commits

Reviewing files that changed from the base of the PR and between 7be4a92 and 08d6d79.

📒 Files selected for processing (2)
  • .github/workflows/ci-security.yaml
  • AGENTS.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The zizmor job now references its reusable workflow with the $/ self-repository syntax. AGENTS.md documents this syntax and states that GitHub resolves the reference against the running commit and treats it as pinned.

Changes

Reusable Workflow Reference

Layer / File(s) Summary
Update reusable workflow reference
AGENTS.md, .github/workflows/ci-security.yaml
AGENTS.md documents the $/ syntax and its resolution behavior. The zizmor job uses this syntax and removes the zizmor: ignore[self-repository] comment.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 08d6d

The security workflow reference resolves to the matching workflow at the running commit, with no call-interface change. It appears ready for GitHub.com; confirm first if GitHub Enterprise Server is a required execution environment, as this syntax is unavailable there.

Architecture Summary

Architecture risk: 🔵 Low · up to 08d6d

The change affects 1 system.

Changed systems: AGENTS.md

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — AGENTS.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in AGENTS.md: The guidance removes the local ./.github/workflows/... call example and directs internal workflow calls to use $/; it adds an explanation that GitHub resolves the reference at the running commit and counts it as pinned.
  • observed — Modified behavior in .github/workflows/ci-security.yaml: The zizmor job’s reusable-workflow reference changed from the local ./.github/workflows/reusable-ci-security.yaml path to $/ .github/workflows/reusable-ci-security.yaml; the zizmor: ignore[self-repository] comment was removed.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: using self-repository syntax for in-repository reusable workflow calls.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the workflow call,
The $/ path now guides them all.
The running commit sets the view,
The guide records the rule as true.
One hop, one note, then off they go,
With twitching ears and tidy flow.

Comment @coderabbitai help to get the list of available commands.

@luxass
luxass merged commit 34e3ba9 into main Sep 27, 2026
4 checks passed
@luxass
luxass deleted the chore/self-repository-syntax branch September 27, 2026 04:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant