Add zizmor as a CI check (#2776)

* Add zizmor as a CI check

I'm curious about adding this tool, so experimenting with it here...

See #2770 for the impetus.

* Lie about a tag to see what happens

* Revert "Lie about a tag to see what happens"

This reverts commit f0e78b8c92c2d00f71d44e83d7904d8728427341.
This commit is contained in:
Joe Rickerby
2026-03-16 19:55:13 +00:00
committed by GitHub
parent 741be9402c
commit 35452dcd42
+24
View File
@@ -0,0 +1,24 @@
name: zizmor - GitHub Actions Security Analysis
on:
push:
branches: ["main"]
pull_request:
branches: ["**"]
permissions: {}
jobs:
zizmor:
name: Run zizmor 🌈
runs-on: ubuntu-latest
permissions:
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Run zizmor 🌈
uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2