yossarian (1.3.6.1.4.1.55738)

@yossarian@infosec.exchange
1.4K Followers
134 Following
1.1K Posts

open source interloper; attracts bugs easily

אַ ביסל ייִדיש־פּאָסטינג

websitehttps://yossarian.net
bloghttps://blog.yossarian.net
githubhttps://github.com/woodruffw
blueskyhttps://bsky.app/profile/yossarian.net

zizmor v1.11.0 is released!

this is a much smaller release than v1.10.0, but it comes with an experimental feature that's been in the works for a long time: LSP support!

with `zizmor --lsp` you can now integrate zizmor directly into your editor/IDE. we even have an (experimental) vscode extension already: https://marketplace.visualstudio.com/items?itemName=zizmor.zizmor-vscode

see the full notes here: https://docs.zizmor.sh/release-notes/

#rust #security #opensource #github

what’s the matter babe? you haven’t touched your 50 pounds of raisinettes
i deeply dislike that this parses correctly in GHA
אַ פֿרײַלאַך פּראַיד
compare to the old render, which knew which part of the code block was problematic but couldn't span it discretely:

sneak peek for more precise subspanning within zizmor:

(this overcomes one of zizmor's earliest architectural limitations, i.e. that it could only span on full YAML elements and nothing within those elements. no longer!)

zizmor now has a splash page!

https://zizmor.sh/

there's something pathological about corporations that make them think that disrespecting their users like this somehow works in their favor. i didn't want this feature, would happily disable it if they let me, and am now looking for an alternative. i use gsuite for email and basic docs storage, not for anything else.
deep cut Python fan

this is the kind of stuff that makes me very happy: curl has been using zizmor for their CI/CD, and have hit a point where zizmor has unblocked shellcheck, meaning that it's enabled them to fix problems found by *other* tools!

https://github.com/curl/curl/commit/17a669426f36b467dfd945b4b35f6211598b7977