ci: add shared security scanning workflow - #5708
opentelemetrybot wants to merge 4 commits into
Conversation
Pin and scope workflow dependencies, pass PR metadata through environments, and document the remaining publishing exceptions. Assisted-by: GitHub Copilot
Assisted-by: GitHub Copilot
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Pull request dashboard statusWaiting on reviewers · refreshed 2026-09-30 23:41 UTC Review the latest changes. Also blocked by: 1 required status check is failing. Status above doesn't look right?
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The generated CI workflow and its template contain invalid local reusable-workflow references that prevent core CI jobs from loading.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds shared Zizmor security scanning and remediates related workflow findings.
Changes:
- Adds scheduled, push, and PR security scanning with documented exceptions.
- Hardens workflow inputs, permissions, and action references.
- Adds a Dependabot cooldown.
| File | Description |
|---|---|
.github/zizmor.yml |
Configures justified Zizmor exclusions. |
.github/workflows/zizmor.yml |
Invokes the pinned shared scanning workflow. |
.github/workflows/templates/ci.yml.j2 |
Pins contrib CI but introduces invalid local workflow paths. |
.github/workflows/prepare-release-branch.yml |
Narrows app-token permissions and safely passes PR URLs. |
.github/workflows/prepare-patch-release.yml |
Hardens app-token permissions and PR URL handling. |
.github/workflows/ci.yml |
Pins contrib CI but introduces invalid local workflow paths. |
.github/workflows/check-links.yml |
Safely transports changed filenames as JSON. |
.github/workflows/changelog.yml |
Moves GitHub expressions into quoted environment variables. |
.github/workflows/backport.yml |
Restricts the app token to PR write access. |
.github/workflows/add-to-project.yml |
Restricts project-board token permissions. |
.github/dependabot.yml |
Adds a seven-day update cooldown. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
we should probably get rid of that as we are using renovate
There was a problem hiding this comment.
can you send this as a follow-up? trying to keep these bot PRs focused
| uses: $/.github/workflows/test.yml | ||
| contrib: | ||
| uses: open-telemetry/opentelemetry-python-contrib/.github/workflows/core_contrib_test.yml@main | ||
| uses: open-telemetry/opentelemetry-python-contrib/.github/workflows/core_contrib_test.yml@94a9acc9b4d2943079eea2076289777e5e0dbc7a |
There was a problem hiding this comment.
can we keep it pointing to main?
Assisted-by: GPT-6.1 Sol Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Description
Tracked in open-telemetry/sig-security#293.
Adds zizmor scanning through the OpenTelemetry shared workflow. It runs on pull requests, pushes to
mainandrelease/*, and a weekly schedule, with findings uploaded to code scanning.The same change scopes GitHub App token permissions and passes PR-derived values through environment variables instead of embedding them in shell scripts. The link checker now passes changed filenames safely. Line-scoped zizmor exceptions retain the existing pinned link-check CLI and token-based TestPyPI/PyPI publishing until trusted publishers are configured.
The contrib integration workflow continues to follow
main. A workflow-specific Zizmor policy permits symbolic references for that workflow while requiring SHA pins elsewhere. No contrib repository change is required.After merge
zizmorresult.If enforcement blocks a valid change, restore
require_zizmor = falseinopen-telemetry/adminwhile leaving scanning enabled.Type of change
How Has This Been Tested?
Local checks used Python 3.12.10 and Zizmor 1.29.0 on Windows.
python .github\workflows\generate_workflows.py: passed; generated CI matches its template.zizmor --offline --no-progress --no-ignores --config .github\zizmor.yml --format json .github\workflows\ci.yml: passed with no findings.git diff --check: passed.tox -q -e generate-workflows: failed while downloading dependencies because of a TLS handshake error; the generator was then run successfully with installed dependencies using the command above.Temporary workflow fixtures confirmed that the policy survives renamed files and shifted lines, allows symbolic references for the specified contrib workflow, and still flags unpinned references to other workflows, repositories, and actions. Online audits and the full Python test suite were not run locally.
Does This PR Require a Contrib Repo Change?
Checklist: