Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 9 additions & 5 deletions .github/workflows/ci.yml → .github/workflows/publish.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,14 @@
name: CI
name: Publish

# Default permissions are least-privilege; the publish job elevates to
# contents: write / packages: write below. This satisfies zizmor's
# excessive-permissions check.
permissions:
contents: read

on:
push:
branches: [main]
tags: ['v*']
pull_request:
branches: [main]

jobs:
test:
Expand Down Expand Up @@ -34,8 +37,9 @@ jobs:
publish:
name: Publish to GitHub Packages
runs-on: ubuntu-latest
# Tag pushes can't depend on the separate Test workflow, so tests are
# re-run here and the publish job is gated on them succeeding.
needs: test
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
permissions:
contents: write
packages: write
Expand Down
43 changes: 43 additions & 0 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
name: Test

# Default permissions are least-privilege; no job needs elevated access.
# This satisfies zizmor's excessive-permissions check.
permissions:
contents: read

# A newer push to the same ref cancels any older run that is still
# in progress, so superseded runs don't tie up runners or produce
# stale check results.
concurrency:
group: test-${{ github.ref }}
cancel-in-progress: true

on:
push:
branches: [main]
pull_request:
branches: [main]

jobs:
test:
name: Build & Test
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WARNING: Action version pinned to a major-version tag, not a SHA commit

The PR description claims this matches docker.yml's "zizmor-compliant style", but docker.yml pins every action to a SHA + version comment (e.g. actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2). Pinning to @v4 here still trips zizmor's unpinned-uses audit, so the new permissions: contents: read block only fixes the excessive-permissions audit — the unpinned-uses finding remains. The same fix is needed for actions/setup-java@v5 (line 30) and actions/upload-artifact@v4 (line 40).

Suggested change
uses: actions/checkout@v4
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

Reply with @kilocode-bot fix it to have Kilo Code address this issue.


- name: Set up JDK 17
uses: actions/setup-java@v5
with:
distribution: 'temurin'
java-version: '17'

- name: Run tests
run: gradle --no-daemon test

- name: Upload test results
if: always()
uses: actions/upload-artifact@v4
with:
name: test-results
path: build/reports/tests/test/
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# Synapse

[![CI](https://github.com/IamCoder18/synapse/actions/workflows/ci.yml/badge.svg)](https://github.com/IamCoder18/synapse/actions/workflows/ci.yml)
[![Test](https://github.com/IamCoder18/synapse/actions/workflows/test.yml/badge.svg)](https://github.com/IamCoder18/synapse/actions/workflows/test.yml)
[![Publish](https://github.com/IamCoder18/synapse/actions/workflows/publish.yml/badge.svg)](https://github.com/IamCoder18/synapse/actions/workflows/publish.yml)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](./LICENSE)
[![Latest release](https://img.shields.io/github/v/tag/IamCoder18/synapse?label=release)](https://github.com/IamCoder18/synapse/releases)
[![Maven Package](https://img.shields.io/badge/Maven-GitHub%20Packages-blue)](https://github.com/IamCoder18/synapse/packages)
Expand Down
Loading