File tree Expand file tree Collapse file tree 1 file changed +35
-0
lines changed Expand file tree Collapse file tree 1 file changed +35
-0
lines changed Original file line number Diff line number Diff line change 1+ on :
2+ pull_request :
3+
4+ name : Security (Testing)
5+
6+ permissions :
7+ contents : read
8+
9+ jobs :
10+ zizmor :
11+ name : zizmor latest via PyPI
12+ runs-on : ubuntu-latest
13+ permissions :
14+ security-events : write # needed for SARIF uploads
15+ contents : read # only needed for private repos
16+ actions : read # only needed for private repos
17+ steps :
18+ - name : Checkout repository
19+ uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
20+ with :
21+ persist-credentials : false
22+
23+ - name : Install the latest version of uv
24+ uses : astral-sh/setup-uv@85856786d1ce8acfbcc2f13a5f3fbd6b938f9f41 # v7.1.2
25+
26+ - name : Run zizmor 🌈
27+ run : uvx zizmor --format=sarif . > results.sarif
28+ env :
29+ GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
30+
31+ - name : Upload SARIF file
32+ uses : github/codeql-action/upload-sarif@4e94bd11f71e507f7f87df81788dff88d1dacbfb # v4.31.0
33+ with :
34+ sarif_file : results.sarif
35+ category : zizmor
You can’t perform that action at this time.
0 commit comments