Skip to content

Commit 82913cf

Browse files
committed
Add zizmor workflow to audit GitHub Actions workflows
Runs zizmor on changes to .github/** to catch common security issues in CI workflows such as unpinned actions and injection risks. Signed-off-by: Dan Childers <dchilder@redhat.com>
1 parent 2b24136 commit 82913cf

1 file changed

Lines changed: 28 additions & 0 deletions

File tree

‎.github/workflows/zizmor.yml‎

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
name: zizmor
2+
3+
on:
4+
push:
5+
branches:
6+
- main
7+
paths:
8+
- '.github/**'
9+
pull_request:
10+
paths:
11+
- '.github/**'
12+
13+
permissions: {}
14+
15+
jobs:
16+
zizmor:
17+
runs-on: ubuntu-latest
18+
permissions:
19+
security-events: write
20+
contents: read
21+
steps:
22+
- name: Checkout repository
23+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
24+
with:
25+
persist-credentials: false
26+
27+
- name: Run zizmor
28+
uses: zizmorcore/zizmor-action@192e21d79ab29983730a13d1382995c2307fbcaa # v0.5.7

0 commit comments

Comments
 (0)