From 9fc48bbd8857e79d2ec52d901e98cbe20b45b8a8 Mon Sep 17 00:00:00 2001 From: Marius Merschformann Date: Tue, 12 May 2026 13:14:57 +0200 Subject: [PATCH 1/4] Add zizmor workflow for GitHub Actions security analysis --- .github/workflows/zizmor.yml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..1e63bb2 --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,26 @@ +name: zizmor + +on: + push: + branches: ["main"] + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + name: Run zizmor 🌈 + runs-on: ubuntu-latest + permissions: + security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files. + contents: read # Only needed for private repos. Needed to clone the repo. + actions: read # Only needed for private repos. Needed for upload-sarif to read workflow run info. + steps: + - name: Checkout repository + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Run zizmor 🌈 + uses: zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3 From 1a496305869af65c402797ee191214b3820768e4 Mon Sep 17 00:00:00 2001 From: Marius Merschformann Date: Tue, 12 May 2026 13:24:17 +0200 Subject: [PATCH 2/4] Remove emoji from zizmor workflow --- .github/workflows/zizmor.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 1e63bb2..3f82513 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -10,7 +10,7 @@ permissions: {} jobs: zizmor: - name: Run zizmor 🌈 + name: Run zizmor runs-on: ubuntu-latest permissions: security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files. @@ -22,5 +22,5 @@ jobs: with: persist-credentials: false - - name: Run zizmor 🌈 + - name: Run zizmor uses: zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3 From 77874f9fd0432f925d86fbc1853e3b10a273d9f4 Mon Sep 17 00:00:00 2001 From: Marius Merschformann Date: Tue, 12 May 2026 15:17:14 +0200 Subject: [PATCH 3/4] Update zizmor workflow --- .github/workflows/zizmor.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 3f82513..fc520e5 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -14,8 +14,8 @@ jobs: runs-on: ubuntu-latest permissions: security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files. - contents: read # Only needed for private repos. Needed to clone the repo. - actions: read # Only needed for private repos. Needed for upload-sarif to read workflow run info. + contents: read + actions: read steps: - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 From 9c21338a255d17ee42d877d7197187a590ae58fd Mon Sep 17 00:00:00 2001 From: Marius Merschformann Date: Wed, 13 May 2026 14:40:54 +0200 Subject: [PATCH 4/4] Fix default branch name in zizmor workflow --- .github/workflows/zizmor.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index fc520e5..6b38282 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -2,7 +2,7 @@ name: zizmor on: push: - branches: ["main"] + branches: ["develop"] pull_request: branches: ["**"]