File tree Expand file tree Collapse file tree 1 file changed +32
-0
lines changed Expand file tree Collapse file tree 1 file changed +32
-0
lines changed Original file line number Diff line number Diff line change
1
+ name : GitHub Actions Security Analysis with zizmor
2
+
3
+ on :
4
+ push :
5
+ branches : ["main"]
6
+ pull_request :
7
+ branches : ["**"]
8
+
9
+ jobs :
10
+ zizmor :
11
+ name : zizmor latest via Cargo
12
+ runs-on : ubuntu-latest
13
+ permissions :
14
+ security-events : write
15
+ steps :
16
+ - name : Checkout repository
17
+ uses : actions/checkout@v4
18
+ with :
19
+ persist-credentials : false
20
+ - name : Setup Rust
21
+ uses : actions-rust-lang/setup-rust-toolchain@v1
22
+ - name : Get zizmor
23
+ run : cargo install zizmor
24
+ - name : Run zizmor
25
+ run : zizmor --format sarif . > results.sarif
26
+ env :
27
+ GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
28
+ - name : Upload SARIF file
29
+ uses : github/codeql-action/upload-sarif@v3
30
+ with :
31
+ sarif_file : results.sarif
32
+ category : zizmor
You can’t perform that action at this time.
0 commit comments