Repository navigation
Use compatible local zizmor and poutine scanners when available - #66918
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
Poutine detection uses an unsupported flag, and scanner tests have host-dependent PATH and symlink assumptions.
4 open findings
What changed in this PR
This PR adds local-scanner selection to gh-aw compilation while retaining pinned Docker fallbacks.
Changes:
- Prefer local zizmor ≥ 1.30.1 and poutine ≥ 1.1.6.
- Adjust MCP Docker preparation and add selection tests and documentation.
- Refresh generated workflow schemas to allow null milestones.
| File | Description |
|---|---|
| pkg/cli/zizmor.go | Select local zizmor before Docker. |
| pkg/cli/scanner_local.go | Detect compatible scanner versions. |
| pkg/cli/scanner_local_test.go | Test selection and Docker fallback. |
| pkg/cli/poutine.go | Share local-or-Docker command construction. |
| pkg/cli/mcp_tools_readonly.go | Preserve local scanners without Docker. |
| pkg/cli/docker_images.go | Skip images for compatible local scanners. |
| docs/src/content/docs/setup/cli.md | Document minimum versions and fallback. |
| .github/workflows/workflow-health-manager.lock.yml | Allow null milestones. |
| .github/workflows/workflow-generator.lock.yml | Allow null milestones. |
| .github/workflows/sub-issue-closer.lock.yml | Allow null milestones. |
| .github/workflows/smoke-ci.lock.yml | Allow null milestones. |
| .github/workflows/pr-sous-chef.lock.yml | Allow null milestones. |
| .github/workflows/poem-bot.lock.yml | Allow null milestones. |
| .github/workflows/lint-monster.lock.yml | Allow null milestones. |
| .github/workflows/eslint-monster.lock.yml | Allow null milestones. |
| .github/workflows/daily-squid-image-scan.lock.yml | Allow null milestones. |
| .github/workflows/bot-detection.lock.yml | Allow null milestones. |
| .github/workflows/aw-failure-investigator.lock.yml | Allow null milestones. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
| if opts.Zizmor && localScannerPath(ctxutil.OrBackground(ctx), "zizmor") != "" { | ||
| opts.Zizmor = false |
There was a problem hiding this comment.
Added an isolated PATH to Docker-fallback tests that request zizmor or poutine, preventing host-installed scanners from bypassing the Docker mocks. Commit: 6270c641.
| if err := os.Remove(poutine); err != nil { | ||
| t.Fatal(err) | ||
| } | ||
| cmd, args, err = buildPoutineCommand(root) |
There was a problem hiding this comment.
The fallback assertion now temporarily restricts PATH to the fixture directory, then restores the original PATH before the test continues. Commit: 6270c641.
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 022f812
|
…or-zizmor-poutine Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
🎉 This pull request is included in a new release. Release: |


Compilation currently requires Docker for zizmor and poutine even when the scanners are installed locally. This change checks local versions automatically and retains the pinned Docker images as fallback.