chore: delete repo-local zizmor.yml - #29
Merged
Merged
Conversation
It was a byte-identical copy of smartwatermelon/github-workflows/zizmor.yml. standards-check falls back to that canonical policy when a repo has no root zizmor.yml (run-standards.sh, at standards-check-v1), and the local pre-commit hook passes the canonical config explicitly since smartwatermelon/dotfiles#344. The copy only added a place for the policy to drift. Closes #25
|
The PR deletes No file in this repo references The deletion makes zizmor checks stricter (removing suppression rules), not more permissive, so it does not introduce a security regression. VERDICT: PASS |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
It was a byte-identical copy of smartwatermelon/github-workflows/zizmor.yml.
standards-check falls back to that canonical policy when a repo has no
root zizmor.yml (run-standards.sh, at standards-check-v1), and the local
pre-commit hook passes the canonical config explicitly since
smartwatermelon/dotfiles#344. The copy only added a place for the policy
to drift.
Closes #25
AGENTS.md stays tracked here on purpose: it is the canonical context file and CLAUDE.md is a symlink to it (carve-out from smartwatermelon/dev-env#155).