Skip to content

chore: delete repo-local zizmor.yml - #29

Merged
twistedmelonman merged 1 commit into
mainfrom
claude/chore-fleet-sweep-8a854048
Sep 25, 2026
Merged

twistedmelonman merged 1 commit into
mainfrom
claude/chore-fleet-sweep-8a854048

Conversation

@twistedmelonman

Copy link
Copy Markdown
Member

It was a byte-identical copy of smartwatermelon/github-workflows/zizmor.yml.
standards-check falls back to that canonical policy when a repo has no
root zizmor.yml (run-standards.sh, at standards-check-v1), and the local
pre-commit hook passes the canonical config explicitly since
smartwatermelon/dotfiles#344. The copy only added a place for the policy
to drift.

Closes #25

AGENTS.md stays tracked here on purpose: it is the canonical context file and CLAUDE.md is a symlink to it (carve-out from smartwatermelon/dev-env#155).

It was a byte-identical copy of smartwatermelon/github-workflows/zizmor.yml.
standards-check falls back to that canonical policy when a repo has no
root zizmor.yml (run-standards.sh, at standards-check-v1), and the local
pre-commit hook passes the canonical config explicitly since
smartwatermelon/dotfiles#344. The copy only added a place for the policy
to drift.

Closes #25
@claude

claude Bot commented Sep 25, 2026

Copy link
Copy Markdown

The PR deletes zizmor.yml, the documented zizmor security-scanner configuration for this repo and a fleet-wide fallback policy for consumer repos per the file comments.

No file in this repo references zizmor.yml directly. The claimed fleet-wide fallback role via standards-check.yml is described only in comments inside the deleted file; there is no in-repo execution path that would break on deletion.

The deletion makes zizmor checks stricter (removing suppression rules), not more permissive, so it does not introduce a security regression.

VERDICT: PASS

@twistedmelonman
twistedmelonman merged commit b7c3bd2 into main Sep 25, 2026
10 checks passed
@twistedmelonman
twistedmelonman deleted the claude/chore-fleet-sweep-8a854048 branch September 25, 2026 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Delete repo-local zizmor.yml — canonical config now resolves from github-workflows

1 participant