File tree Expand file tree Collapse file tree 1 file changed +37
-0
lines changed
Expand file tree Collapse file tree 1 file changed +37
-0
lines changed Original file line number Diff line number Diff line change 1+ name : GitHub Actions Security Analysis with zizmor 🌈
2+
3+ on :
4+ push :
5+ branches : ["main"]
6+ pull_request :
7+ branches : ["**"]
8+
9+ permissions : {}
10+
11+ jobs :
12+ zizmor :
13+ name : zizmor latest via PyPI
14+ runs-on : ubuntu-latest
15+ permissions :
16+ security-events : write # needed for SARIF uploads
17+ contents : read # only needed for private repos
18+ actions : read # only needed for private repos
19+ steps :
20+ - name : Checkout repository
21+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
22+ with :
23+ persist-credentials : false
24+
25+ - name : Install the latest version of uv
26+ uses : astral-sh/setup-uv@6b9c6063abd6010835644d4c2e1bef4cf5cd0fca # v6.0.1
27+
28+ - name : Run zizmor 🌈
29+ run : uvx zizmor --format=sarif . > results.sarif
30+ env :
31+ GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
32+
33+ - name : Upload SARIF file
34+ uses : github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
35+ with :
36+ sarif_file : results.sarif
37+ category : zizmor
You can’t perform that action at this time.
0 commit comments