Skip to content

Clarify that the license key in pyproject.toml should only be set if it is consistent across all distribution files #598

Clarify that the license key in pyproject.toml should only be set if it is consistent across all distribution files

Clarify that the license key in pyproject.toml should only be set if it is consistent across all distribution files #598

Workflow file for this run

# From https://woodruffw.github.io/zizmor/usage/#use-in-github-actions
name: GitHub Actions Security Analysis with zizmor 🌈
on:
push:
branches: ["main"]
pull_request:
branches: ["**"]
jobs:
zizmor:
name: zizmor latest via PyPI
runs-on: ubuntu-latest
permissions:
security-events: write
# required for workflows in private repositories
contents: read
actions: read
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
persist-credentials: false
- name: Install the latest version of uv
uses: astral-sh/setup-uv@v5
- name: Run zizmor 🌈
run: uvx zizmor --format sarif source/guides/github-actions-ci-cd-sample/* > results.sarif
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: results.sarif
category: zizmor