We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 6052cac commit 5e619dcCopy full SHA for 5e619dc
2 files changed
.github/workflows/ci-additional.yaml
@@ -335,3 +335,17 @@ jobs:
335
- name: All-deps minimum versions policy
336
run: |
337
pixi run policy-min-versions
338
+
339
+ zizmor:
340
+ name: GHA Security Analysis using Zizmor
341
+ runs-on: ubuntu-latest
342
+ permissions:
343
+ security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files.
344
+ steps:
345
+ - name: Checkout repository
346
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
347
+ with:
348
+ persist-credentials: false
349
350
+ - name: Run zizmor
351
+ uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2
.pre-commit-config.yaml
@@ -83,3 +83,4 @@ repos:
83
rev: v1.23.1
84
hooks:
85
- id: zizmor
86
+ args: ["--offline"]
0 commit comments