name: zizmor on: pull_request: branches: - main push: branches: - main permissions: contents: read # Needed to checkout the repository. concurrency: group: "${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.sha }}" cancel-in-progress: true jobs: zizmor: name: zizmor runs-on: ubuntu-latest permissions: security-events: write # Needed to upload code scanning results. contents: read # Needed to checkout the repository. actions: read # Needed to analyze action metadata. steps: - name: harden runner uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2 with: egress-policy: audit - name: checkout uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 with: persist-credentials: false - name: setup uv uses: astral-sh/setup-uv@85856786d1ce8acfbcc2f13a5f3fbd6b938f9f41 # v7.1.2 - name: zizmor run: uvx zizmor --pedantic --format sarif . > results.sarif env: GH_TOKEN: "${{ secrets.GITHUB_TOKEN }}" - name: upload uses: github/codeql-action/upload-sarif@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2 with: sarif_file: results.sarif category: zizmor