Skip to content

Commit 799aecf

Browse files
authored
Refactor Zizmor workflow to use zizmor-action
Same stuff, but delegate how Zizmor gets installed to zizmor-action.
1 parent 6e385a2 commit 799aecf

File tree

1 file changed

+3
-15
lines changed

1 file changed

+3
-15
lines changed

.github/workflows/zizmor.yml

Lines changed: 3 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -10,28 +10,16 @@ permissions: {}
1010

1111
jobs:
1212
zizmor:
13-
name: zizmor latest via PyPI
1413
runs-on: ubuntu-latest
1514
permissions:
1615
security-events: write # needed for SARIF uploads
17-
contents: read # only needed for private repos
18-
actions: read # only needed for private repos
16+
contents: read # only needed for private or internal repos
17+
actions: read # only needed for private or internal repos
1918
steps:
2019
- name: Checkout repository
2120
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
2221
with:
2322
persist-credentials: false
2423

25-
- name: Install the latest version of uv
26-
uses: astral-sh/setup-uv@681c641aba71e4a1c380be3ab5e12ad51f415867 # v7.1.6
27-
2824
- name: Run zizmor 🌈
29-
run: uvx zizmor --format=sarif . > results.sarif
30-
env:
31-
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
32-
33-
- name: Upload SARIF file
34-
uses: github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
35-
with:
36-
sarif_file: results.sarif
37-
category: zizmor
25+
uses: zizmorcore/zizmor-action@135698455da5c3b3e55f73f4419e481ab68cdd95 # v0.4.1

0 commit comments

Comments
 (0)