Skip to content

Commit 63f60fe

Browse files
MAINT: Add Zizmor as GHA (#2573)
1 parent 2a989a7 commit 63f60fe

File tree

2 files changed

+15
-0
lines changed

2 files changed

+15
-0
lines changed

.github/workflows/ci.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -243,3 +243,17 @@ jobs:
243243
done
244244
env:
245245
PREFIX_API_KEY: ${{ secrets.PREFIX_API_KEY }} # zizmor: ignore[secrets-outside-env]
246+
247+
zizmor:
248+
name: GHA Security Analysis using Zizmor
249+
runs-on: ubuntu-latest
250+
permissions:
251+
security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files.
252+
steps:
253+
- name: Checkout repository
254+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
255+
with:
256+
persist-credentials: false
257+
258+
- name: Run zizmor
259+
uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2

.pre-commit-config.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ repos:
1313
rev: v1.23.1
1414
hooks:
1515
- id: zizmor
16+
args: ["--offline"]
1617
- repo: https://github.com/astral-sh/ruff-pre-commit
1718
rev: v0.15.9
1819
hooks:

0 commit comments

Comments
 (0)