Skip to content

Feature: Depot CI Support #1803

@cedws

Description

@cedws

Pre-submission checks

  • I am not reporting a bug (crash, false positive/negative, etc). These must be filed via the bug report template.
  • I have looked through both the open and closed issues for a duplicate request.

What's the problem this feature will solve?

Depot CI recently released: https://depot.dev/blog/now-available-depot-ci

Depot CI workflows are separate from GitHub workflows and live in .depot. Although Zizmor does not search inside .depot, it can be ran manually against individual Depot workflow files. This works currently because Depot workflows are largely compatible (for now.)

This feature request is for asking whether Zizmor will support Depot workflows given these assumptions:

  • There will be larger divergences in future
  • Depot CI is a commercial product and the spec is not open source

See here for compatibility matrix: https://depot.dev/docs/ci/compatibility

Describe the solution you'd like

A short term solution could be to add .depot as a search path for Zizmor, but this could be broken. I'm not sure what kind of compatibility Depot workflows will have in future.

Additional context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestlong-termsponsorable:10kFundable improvement via GitHub sponsors; see https://github.com/sponsors/woodruffw

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions