File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ name : GitHub Actions Security Analysis with zizmor 🌈
2+
3+ on :
4+ push :
5+ branches : ["main"]
6+ pull_request :
7+ branches : ["**"]
8+
9+ permissions : {}
10+
11+ jobs :
12+ zizmor :
13+ name : Run zizmor 🌈
14+ runs-on : ubuntu-latest
15+ permissions :
16+ security-events : write # Required for upload-sarif (used by zizmor-action) to upload SARIF files.
17+ contents : read # Only needed for private repos. Needed to clone the repo.
18+ actions : read # Only needed for private repos. Needed for upload-sarif to read workflow run info.
19+ steps :
20+ - name : Checkout repository
21+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
22+ with :
23+ persist-credentials : false
24+
25+ - name : Run zizmor 🌈
26+ uses : zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3
You can’t perform that action at this time.
0 commit comments