Harden CI's security posture - #9266
Conversation
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
|
For future work we can also use |
Merging this PR will degrade performance by 45.44%
|
| Mode | Benchmark | BASE |
HEAD |
Efficiency | |
|---|---|---|---|---|---|
| ❌ | Simulation | decompress[u64, (1000, 16)] |
72.9 µs | 133.5 µs | -45.44% |
Tip
Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.
Comparing adamg/zizmor (13afa0d) with develop (6a8d248)
Footnotes
-
8 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Signed-off-by: Adam Gutglick <adam@spiraldb.com>
Polar Signals Profiling ResultsLatest Run
Powered by Polar Signals Cloud |
Benchmarks: String Encoding 📖vortex / vortex-file-compressed / ms (0.994x ➖, 0↑ 0↓)
vortex / vortex-file-compressed / % (1.000x ➖, 0↑ 0↓)
|
Benchmarks: TPC-H SF=1 on NVME 📖Verdict: No clear signal (low confidence) How to read Verdict and Engines
datafusion / vortex-file-compressed / ns (1.005x ➖, 0↑ 0↓)
datafusion / parquet / ns (0.978x ➖, 3↑ 1↓)
duckdb / vortex-file-compressed / ns (1.001x ➖, 1↑ 0↓)
duckdb / parquet / ns (0.994x ➖, 0↑ 0↓)
File Size Changes (9 files changed, -43.9% overall, 0↑ 9↓)
Totals:
|
Benchmarks: Clickbench Sorted on NVME 📖Verdict: No clear signal (environment too noisy confidence) How to read Verdict and Engines
datafusion / vortex-file-compressed / ns (0.903x ➖, 2↑ 0↓)
datafusion / parquet / ns (0.994x ➖, 1↑ 1↓)
duckdb / vortex-file-compressed / ns (1.015x ➖, 0↑ 1↓)
duckdb / parquet / ns (1.010x ➖, 0↑ 1↓)
File Size Changes (201 files changed, -42.7% overall, 51↑ 150↓)
Totals:
|
Benchmarks: TPC-H SF=10 on NVME 📖Verdict: No clear signal (low confidence) How to read Verdict and Engines
datafusion / vortex-file-compressed / ns (0.994x ➖, 0↑ 0↓)
datafusion / parquet / ns (0.999x ➖, 0↑ 0↓)
duckdb / vortex-file-compressed / ns (1.005x ➖, 0↑ 0↓)
duckdb / parquet / ns (0.976x ➖, 2↑ 0↓)
File Size Changes (9 files changed, -44.0% overall, 0↑ 9↓)
Totals:
|
Benchmarks: FineWeb S3 📖Verdict: No clear signal (environment too noisy confidence) How to read Verdict and Engines
datafusion / vortex-file-compressed / ns (1.113x ➖, 0↑ 2↓)
datafusion / parquet / ns (1.009x ➖, 0↑ 0↓)
duckdb / vortex-file-compressed / ns (0.955x ➖, 0↑ 0↓)
duckdb / parquet / ns (0.997x ➖, 1↑ 1↓)
|
Benchmarks: PolarSignals Profiling 📖Vortex (geomean): 1.027x ➖ datafusion / vortex-file-compressed / ns (1.027x ➖, 1↑ 2↓)
No file size changes detected. |
Benchmarks: TPC-DS SF=1 on NVME 📖Verdict: No clear signal (low confidence) How to read Verdict and Engines
datafusion / vortex-file-compressed / ns (1.002x ➖, 0↑ 0↓)
datafusion / parquet / ns (0.998x ➖, 1↑ 2↓)
duckdb / vortex-file-compressed / ns (1.022x ➖, 4↑ 11↓)
duckdb / parquet / ns (1.009x ➖, 3↑ 8↓)
File Size Changes (25 files changed, -43.5% overall, 0↑ 25↓)
Totals:
|
Benchmarks: Clickbench on NVME 📖Verdict: No clear signal (low confidence) How to read Verdict and Engines
datafusion / vortex-file-compressed / ns (0.994x ➖, 1↑ 0↓)
datafusion / parquet / ns (0.995x ➖, 1↑ 0↓)
duckdb / vortex-file-compressed / ns (0.990x ➖, 6↑ 6↓)
duckdb / parquet / ns (1.003x ➖, 0↑ 2↓)
File Size Changes (101 files changed, -39.2% overall, 0↑ 101↓)
Totals:
|
Benchmarks: FineWeb NVMe 📖Verdict: No clear signal (low confidence) How to read Verdict and Engines
datafusion / vortex-file-compressed / ns (0.997x ➖, 1↑ 0↓)
datafusion / parquet / ns (0.980x ➖, 1↑ 0↓)
duckdb / vortex-file-compressed / ns (0.943x ➖, 2↑ 0↓)
duckdb / parquet / ns (0.996x ➖, 0↑ 0↓)
File Size Changes (2 files changed, -46.3% overall, 0↑ 2↓)
Totals:
|
Benchmarks: Statistical and Population Genetics 📖Verdict: No clear signal (low confidence) How to read Verdict and Engines
duckdb / vortex-file-compressed / ns (0.991x ➖, 1↑ 2↓)
duckdb / parquet / ns (0.998x ➖, 0↑ 0↓)
File Size Changes (2 files changed, -32.3% overall, 0↑ 2↓)
Totals:
|
Benchmarks: TPC-H SF=1 on S3 📖Verdict: No clear signal (low confidence) How to read Verdict and Engines
datafusion / vortex-file-compressed / ns (0.852x ➖, 4↑ 0↓)
datafusion / parquet / ns (1.016x ➖, 0↑ 0↓)
duckdb / vortex-file-compressed / ns (1.025x ➖, 0↑ 1↓)
duckdb / parquet / ns (1.012x ➖, 0↑ 0↓)
|
Rationale for this change
Mostly to try and make CI more secure and follow best practices where we can. Most work was done with a combination of zizmor's auto-fix capabilities and some manual review.
I think the critical part to review here is the permissions changes to the publish flows, most other things seem to work correctly.