-
Notifications
You must be signed in to change notification settings - Fork 735
Open
Labels
github_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions codetoolingThis PR affects tooling (CI, pr_labeler, noxfile, linters, etc.) but not the docs builds themselves.This PR affects tooling (CI, pr_labeler, noxfile, linters, etc.) but not the docs builds themselves.
Description
Hey @oraNod, here's an integration you can add through GHA itself:
---
name: GitHub Actions Security Analysis with zizmor 🌈
on: # yamllint disable-line rule:truthy
push:
pull_request:
jobs:
zizmor:
name: 🌈 zizmor
permissions:
security-events: write
# yamllint disable-line rule:line-length
uses: zizmorcore/workflow/.github/workflows/reusable-zizmor.yml@3bb5e95068d0f44b6d2f3f7e91379bed1d2f96a8
...Optionally, it could also be added to pre-commit on top: https://docs.zizmor.sh/usage/#use-with-pre-commit.
It'll reveal a number of problems, each explained @ https://docs.zizmor.sh/audits/.
cc @felixfontein @gotmax23 this might be interesting to you in context of the entire set of community repos.
oraNod and gotmax23
Metadata
Metadata
Assignees
Labels
github_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions codetoolingThis PR affects tooling (CI, pr_labeler, noxfile, linters, etc.) but not the docs builds themselves.This PR affects tooling (CI, pr_labeler, noxfile, linters, etc.) but not the docs builds themselves.
Type
Projects
Status
🆕 Triage