File tree Expand file tree Collapse file tree 5 files changed +41
-0
lines changed
Expand file tree Collapse file tree 5 files changed +41
-0
lines changed Original file line number Diff line number Diff line change 2121 uses : actions/checkout@v4
2222 with :
2323 submodules : true
24+ persist-credentials : false
2425
2526 - name : Install system dependencies
2627 run : sudo apt update && sudo apt install pkg-config clang build-essential libxml2-dev libsqlite3-dev wget libssl-dev libcurl4 zlib1g-dev libcurl4-openssl-dev libonig-dev libzip-dev -y
Original file line number Diff line number Diff line change 2222 uses : actions/checkout@v4
2323 with :
2424 submodules : true
25+ persist-credentials : false
2526
2627 - name : Install clang-tools and libmaxminddb
2728 run : sudo apt update && sudo apt-get install clang-tools libmaxminddb-dev
Original file line number Diff line number Diff line change 1818
1919 - name : Checkout
2020 uses : actions/checkout@v4
21+ with :
22+ persist-credentials : false
2123
2224 - name : Install dependencies
2325 run : composer install --no-progress --prefer-dist --optimize-autoloader
Original file line number Diff line number Diff line change 3535 uses : actions/checkout@v4
3636 with :
3737 submodules : true
38+ persist-credentials : false
3839
3940 - name : Install libmaxminddb
4041 run : |
Original file line number Diff line number Diff line change 1+ name : GitHub Actions Security Analysis with zizmor
2+
3+ on :
4+ push :
5+ branches : ["main"]
6+ pull_request :
7+ branches : ["**"]
8+
9+ jobs :
10+ zizmor :
11+ name : zizmor latest via PyPI
12+ runs-on : ubuntu-latest
13+ permissions :
14+ security-events : write
15+ # required for workflows in private repositories
16+ contents : read
17+ actions : read
18+ steps :
19+ - name : Checkout repository
20+ uses : actions/checkout@v4
21+ with :
22+ persist-credentials : false
23+
24+ - name : Install the latest version of uv
25+ uses : astral-sh/setup-uv@v5
26+
27+ - name : Run zizmor
28+ run : uvx zizmor --format sarif . > results.sarif
29+ env :
30+ GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
31+
32+ - name : Upload SARIF file
33+ uses : github/codeql-action/upload-sarif@v3
34+ with :
35+ sarif_file : results.sarif
36+ category : zizmor
You can’t perform that action at this time.
0 commit comments