File tree Expand file tree Collapse file tree 1 file changed +26
-0
lines changed
Expand file tree Collapse file tree 1 file changed +26
-0
lines changed Original file line number Diff line number Diff line change 1+ name : GitHub Actions Security Analysis with zizmor 🌈
2+
3+ on :
4+ push :
5+ branches : ["main"]
6+ pull_request :
7+ branches : ["**"]
8+
9+ permissions : {}
10+
11+ jobs :
12+ zizmor :
13+ name : Run zizmor 🌈
14+ runs-on : ubuntu-latest
15+ permissions :
16+ security-events : write # Required for upload-sarif (used by zizmor-action) to upload SARIF files.
17+ contents : read # Only needed for private repos. Needed to clone the repo.
18+ actions : read # Only needed for private repos. Needed for upload-sarif to read workflow run info.
19+ steps :
20+ - name : Checkout repository
21+ uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
22+ with :
23+ persist-credentials : false
24+
25+ - name : Run zizmor 🌈
26+ uses : zizmorcore/zizmor-action@e673c3917a1aef3c65c972347ed84ccd013ecda4 # v0.2.0
You can’t perform that action at this time.
0 commit comments