Skip to content

ci: use zizmor to prevent supply chain attacks via GHA #1

ci: use zizmor to prevent supply chain attacks via GHA

ci: use zizmor to prevent supply chain attacks via GHA #1

Workflow file for this run

name: Zizmor
on:
push:
branches: [master, stable, next]
paths:
- '.github/workflows/**'
pull_request:
branches: [master, stable, next]
paths:
- '.github/workflows/**'
workflow_dispatch:
permissions:
contents: read
jobs:
zizmor:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- name: Install zizmor
run: pipx install zizmor
- name: Run zizmor
run: zizmor --min-severity medium .github/workflows/