| 1234567891011121314151617181920212223242526272829303132333435 |
- name: zizmor
- on:
- push:
- paths:
- - ".github/workflows/*.ya?ml"
- pull_request:
- paths:
- - ".github/workflows/*.ya?ml"
- jobs:
- zizmor:
- name: zizmor latest via PyPI
- runs-on: ubuntu-24.04
- permissions:
- security-events: write
- steps:
- - name: Checkout repository
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- with:
- persist-credentials: false
- - name: Install the latest version of uv
- uses: astral-sh/setup-uv@eac588ad8def6316056a12d4907a9d4d84ff7a3b # v7.3.0
- - name: Run zizmor 🌈
- run: uvx zizmor --format sarif . > results.sarif
- env:
- GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- - name: Upload SARIF file
- uses: github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
- with:
- sarif_file: results.sarif
- category: zizmor
|