Skip to content

CI: improve security, add zizmor and trusted publishing #2

CI: improve security, add zizmor and trusted publishing

CI: improve security, add zizmor and trusted publishing #2

Workflow file for this run

name: zizmor
on:
push:
branches:
- main
- v1.**
pull_request:
branches:
- main
- v1.**
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true
jobs:
zizmor:
name: zizmor
runs-on: ubuntu-latest
permissions:
contents: read # needed to clone the repo
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: run zizmor
uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
with:
# Pin the tool, not just the action: the action's `version` input defaults to
# `latest`, so without this a new zizmor release adding an audit would turn CI
# red on unrelated PRs. Bump deliberately.
version: "1.29.0"
advanced-security: false
annotations: true
inputs: .github/