aboutsummaryrefslogtreecommitdiff
path: root/.github/workflows/zizmor.yml
diff options
context:
space:
mode:
Diffstat (limited to '.github/workflows/zizmor.yml')
-rw-r--r--.github/workflows/zizmor.yml35
1 files changed, 35 insertions, 0 deletions
diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml
new file mode 100644
index 0000000..c2a03ab
--- /dev/null
+++ b/.github/workflows/zizmor.yml
@@ -0,0 +1,35 @@
+name: zizmor
+
+on:
+ push:
+ paths:
+ - '.github/workflows/*.ya?ml'
+ pull_request:
+ paths:
+ - '.github/workflows/*.ya?ml'
+
+jobs:
+ zizmor:
+ name: zizmor latest via PyPI
+ runs-on: ubuntu-latest
+ permissions:
+ security-events: write
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+ with:
+ persist-credentials: false
+
+ - name: Install the latest version of uv
+ uses: astral-sh/setup-uv@v5
+
+ - name: Run zizmor 🌈
+ run: uvx zizmor --format sarif . > results.sarif
+ env:
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+
+ - name: Upload SARIF file
+ uses: github/codeql-action/upload-sarif@v3
+ with:
+ sarif_file: results.sarif
+ category: zizmor