From d6abf444f9b7a4869f2184c940d4ff179ef28537 Mon Sep 17 00:00:00 2001 From: Marius Merschformann Date: Tue, 12 May 2026 13:14:24 +0200 Subject: [PATCH 1/4] Add zizmor workflow for GitHub Actions security analysis --- .github/workflows/zizmor.yml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..1e63bb2 --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,26 @@ +name: zizmor + +on: + push: + branches: ["main"] + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + name: Run zizmor 🌈 + runs-on: ubuntu-latest + permissions: + security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files. + contents: read # Only needed for private repos. Needed to clone the repo. + actions: read # Only needed for private repos. Needed for upload-sarif to read workflow run info. + steps: + - name: Checkout repository + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Run zizmor 🌈 + uses: zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3 From 900cb18a3204386fc53b19e675e4ca422a3f52c3 Mon Sep 17 00:00:00 2001 From: Marius Merschformann Date: Tue, 12 May 2026 13:23:58 +0200 Subject: [PATCH 2/4] Remove emoji from zizmor workflow --- .github/workflows/zizmor.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 1e63bb2..3f82513 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -10,7 +10,7 @@ permissions: {} jobs: zizmor: - name: Run zizmor 🌈 + name: Run zizmor runs-on: ubuntu-latest permissions: security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files. @@ -22,5 +22,5 @@ jobs: with: persist-credentials: false - - name: Run zizmor 🌈 + - name: Run zizmor uses: zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3 From a430888fd327bd8fc167dd3f9d2bfc29f6e45da5 Mon Sep 17 00:00:00 2001 From: Marius Merschformann Date: Tue, 12 May 2026 15:16:59 +0200 Subject: [PATCH 3/4] Update zizmor workflow --- .github/workflows/zizmor.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 3f82513..fc520e5 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -14,8 +14,8 @@ jobs: runs-on: ubuntu-latest permissions: security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files. - contents: read # Only needed for private repos. Needed to clone the repo. - actions: read # Only needed for private repos. Needed for upload-sarif to read workflow run info. + contents: read + actions: read steps: - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 From 77ef9103302f5aafeb074f66c7c1f9e17b2cd9a6 Mon Sep 17 00:00:00 2001 From: Marius Merschformann Date: Wed, 13 May 2026 14:40:38 +0200 Subject: [PATCH 4/4] Fix default branch name in zizmor workflow --- .github/workflows/zizmor.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index fc520e5..6b38282 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -2,7 +2,7 @@ name: zizmor on: push: - branches: ["main"] + branches: ["develop"] pull_request: branches: ["**"]