| 1 | name: GitHub Actions Security Analysis with zizmor 🌈 |
| 2 | |
| 3 | on: |
| 4 | push: |
| 5 | branches: ["main"] |
| 6 | pull_request: |
| 7 | branches: ["**"] |
| 8 | |
| 9 | permissions: {} |
| 10 | |
| 11 | jobs: |
| 12 | zizmor: |
| 13 | runs-on: ubuntu-latest |
| 14 | permissions: |
| 15 | security-events: write |
| 16 | steps: |
| 17 | - name: Checkout repository |
| 18 | uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| 19 | with: |
| 20 | persist-credentials: false |
| 21 | |
| 22 | - name: Run zizmor 🌈 |
| 23 | uses: zizmorcore/zizmor-action@6599ee8b7a49aef6a770f63d261d214911a7ce02 # v0.6.0 |
| 24 |