zizmor.yml 924 B

1234567891011121314151617181920212223242526272829303132333435
  1. name: zizmor
  2. on:
  3. push:
  4. paths:
  5. - ".github/workflows/*.ya?ml"
  6. pull_request:
  7. paths:
  8. - ".github/workflows/*.ya?ml"
  9. jobs:
  10. zizmor:
  11. name: zizmor latest via PyPI
  12. runs-on: ubuntu-24.04
  13. permissions:
  14. security-events: write
  15. steps:
  16. - name: Checkout repository
  17. uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  18. with:
  19. persist-credentials: false
  20. - name: Install the latest version of uv
  21. uses: astral-sh/setup-uv@eac588ad8def6316056a12d4907a9d4d84ff7a3b # v7.3.0
  22. - name: Run zizmor 🌈
  23. run: uvx zizmor --format sarif . > results.sarif
  24. env:
  25. GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  26. - name: Upload SARIF file
  27. uses: github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
  28. with:
  29. sarif_file: results.sarif
  30. category: zizmor