From 35452dcd420b9a37f9fc13c75c3564e9c7c56607 Mon Sep 17 00:00:00 2001 From: Joe Rickerby Date: Mon, 16 Mar 2026 19:55:13 +0000 Subject: [PATCH] Add zizmor as a CI check (#2776) * Add zizmor as a CI check I'm curious about adding this tool, so experimenting with it here... See #2770 for the impetus. * Lie about a tag to see what happens * Revert "Lie about a tag to see what happens" This reverts commit f0e78b8c92c2d00f71d44e83d7904d8728427341. --- .github/workflows/zizmor.yml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 00000000..fcd7d97d --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,24 @@ +name: zizmor - GitHub Actions Security Analysis + +on: + push: + branches: ["main"] + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + name: Run zizmor 🌈 + runs-on: ubuntu-latest + permissions: + security-events: write + steps: + - name: Checkout repository + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Run zizmor 🌈 + uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2