Skip to content

ci: add shared security scanning workflow - #5708

Open
opentelemetrybot wants to merge 4 commits into
open-telemetry:mainfrom
opentelemetrybot:zizmor-rollout/post-prereq-20260922-20260922
Open

opentelemetrybot wants to merge 4 commits into
open-telemetry:mainfrom
opentelemetrybot:zizmor-rollout/post-prereq-20260922-20260922

Conversation

@opentelemetrybot

@opentelemetrybot opentelemetrybot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Description

Tracked in open-telemetry/sig-security#293.

Adds zizmor scanning through the OpenTelemetry shared workflow. It runs on pull requests, pushes to main and release/*, and a weekly schedule, with findings uploaded to code scanning.

The same change scopes GitHub App token permissions and passes PR-derived values through environment variables instead of embedding them in shell scripts. The link checker now passes changed filenames safely. Line-scoped zizmor exceptions retain the existing pinned link-check CLI and token-based TestPyPI/PyPI publishing until trusted publishers are configured.

The contrib integration workflow continues to follow main. A workflow-specific Zizmor policy permits symbolic references for that workflow while requiring SHA pins elsewhere. No contrib repository change is required.

After merge

  1. Confirm the Zizmor workflow succeeds on the merged default-branch commit with zero code-scanning findings.
  2. Mark open-telemetry/admin#935 ready and merge it to require zizmor code scanning.
  3. Confirm a later repository PR reports the required zizmor result.

If enforcement blocks a valid change, restore require_zizmor = false in open-telemetry/admin while leaving scanning enabled.

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • This change requires a documentation update

How Has This Been Tested?

Local checks used Python 3.12.10 and Zizmor 1.29.0 on Windows.

  • python .github\workflows\generate_workflows.py: passed; generated CI matches its template.
  • zizmor --offline --no-progress --no-ignores --config .github\zizmor.yml --format json .github\workflows\ci.yml: passed with no findings.
  • git diff --check: passed.
  • tox -q -e generate-workflows: failed while downloading dependencies because of a TLS handshake error; the generator was then run successfully with installed dependencies using the command above.

Temporary workflow fixtures confirmed that the policy survives renamed files and shifted lines, allows symbolic references for the specified contrib workflow, and still flags unpinned references to other workflows, repositories, and actions. Online audits and the full Python test suite were not run locally.

  • Workflow generation and targeted security-policy checks

Does This PR Require a Contrib Repo Change?

  • Yes. - Link to PR:
  • No.

Checklist:

  • Followed the style guidelines of this project
  • Changelogs have been updated
  • Unit tests have been added
  • Documentation has been updated

Pin and scope workflow dependencies, pass PR metadata through environments, and document the remaining publishing exceptions.

Assisted-by: GitHub Copilot
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@opentelemetry-pr-dashboard

opentelemetry-pr-dashboard Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Pull request dashboard status

Waiting on reviewers · refreshed 2026-09-30 23:41 UTC

Review the latest changes.

Also blocked by: 1 required status check is failing.

Status above doesn't look right?
  • Just replied or pushed? Anything around or after the refresh time above may not be picked up yet — give it a few minutes.
  • Anything look wrong? Report it with what you expected; it helps us improve the dashboard.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The generated CI workflow and its template contain invalid local reusable-workflow references that prevent core CI jobs from loading.

Review effort: Balanced
Findings: 2 High severity

Open (2)
What changed in this PR

Adds shared Zizmor security scanning and remediates related workflow findings.

Changes:

  • Adds scheduled, push, and PR security scanning with documented exceptions.
  • Hardens workflow inputs, permissions, and action references.
  • Adds a Dependabot cooldown.
File Description
.github/​zizmor.yml Configures justified Zizmor exclusions.
.github/​workflows/​zizmor.yml Invokes the pinned shared scanning workflow.
.github/​workflows/​templates/​ci.yml.j2 Pins contrib CI but introduces invalid local workflow paths.
.github/​workflows/​prepare-release-branch.yml Narrows app-token permissions and safely passes PR URLs.
.github/​workflows/​prepare-patch-release.yml Hardens app-token permissions and PR URL handling.
.github/​workflows/​ci.yml Pins contrib CI but introduces invalid local workflow paths.
.github/​workflows/​check-links.yml Safely transports changed filenames as JSON.
.github/​workflows/​changelog.yml Moves GitHub expressions into quoted environment variables.
.github/​workflows/​backport.yml Restricts the app token to PR write access.
.github/​workflows/​add-to-project.yml Restricts project-board token permissions.
.github/​dependabot.yml Adds a seven-day update cooldown.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci.yml
Comment thread .github/workflows/templates/ci.yml.j2
@opentelemetrybot
opentelemetrybot marked this pull request as ready for review September 28, 2026 22:59
@opentelemetrybot
opentelemetrybot requested a review from a team as a code owner September 28, 2026 22:59
Comment thread .github/dependabot.yml

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we should probably get rid of that as we are using renovate

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can you send this as a follow-up? trying to keep these bot PRs focused

Comment thread .github/workflows/templates/ci.yml.j2 Outdated
uses: $/.github/workflows/test.yml
contrib:
uses: open-telemetry/opentelemetry-python-contrib/.github/workflows/core_contrib_test.yml@main
uses: open-telemetry/opentelemetry-python-contrib/.github/workflows/core_contrib_test.yml@94a9acc9b4d2943079eea2076289777e5e0dbc7a

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can we keep it pointing to main?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assisted-by: GPT-6.1 Sol
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

5 participants