Skip to content

Commit 38a8fe3

Browse files
committed
🧪 Integrate Zizmor checks into GHA CI/CD 🌈
This linter guards against common insecure setups in GitHub Actions and Workflows. It is authored and maintained by a member of the PyPA, contributor to PyPI, former employee of the Trail Of Bits. Ref: https://zizmor.sh
1 parent 99511ef commit 38a8fe3

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

.github/workflows/ci.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -450,3 +450,11 @@ jobs:
450450
with:
451451
name: awx-collection-integration-coverage-html
452452
path: ~/.ansible/collections/ansible_collections/awx/awx/tests/output/reports/coverage
453+
454+
zizmor:
455+
name: 🌈 zizmor
456+
permissions:
457+
security-events: write
458+
459+
# yamllint disable-line rule:line-length
460+
uses: zizmorcore/workflow/.github/workflows/reusable-zizmor.yml@3bb5e95068d0f44b6d2f3f7e91379bed1d2f96a8

0 commit comments

Comments
 (0)