Skip to content

Commit 92601de

Browse files
MAINT: Add Zizmor to CI and set hook to "offline" mode (#11294)
1 parent c68b25b commit 92601de

File tree

2 files changed

+15
-0
lines changed

2 files changed

+15
-0
lines changed

.github/workflows/ci-additional.yaml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -335,3 +335,17 @@ jobs:
335335
- name: All-deps minimum versions policy
336336
run: |
337337
pixi run policy-min-versions
338+
339+
zizmor:
340+
name: GHA Security Analysis using Zizmor
341+
runs-on: ubuntu-latest
342+
permissions:
343+
security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files.
344+
steps:
345+
- name: Checkout repository
346+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
347+
with:
348+
persist-credentials: false
349+
350+
- name: Run zizmor
351+
uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2

.pre-commit-config.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -83,3 +83,4 @@ repos:
8383
rev: v1.23.1
8484
hooks:
8585
- id: zizmor
86+
args: ["--offline"]

0 commit comments

Comments
 (0)