Skip to content

Commit 530362f

Browse files
authored
Merge pull request #154 from target/zizmor-update
Update zizmor.yml
2 parents e1e5dce + 91059ab commit 530362f

File tree

1 file changed

+9
-8
lines changed

1 file changed

+9
-8
lines changed

.github/workflows/zizmor.yml

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -6,31 +6,32 @@ on:
66
pull_request:
77
branches: ["**"]
88

9+
permissions: {}
10+
911
jobs:
1012
zizmor:
1113
name: zizmor latest via PyPI
1214
runs-on: ubuntu-latest
1315
permissions:
1416
security-events: write
15-
# required for workflows in private repositories
16-
contents: read
17-
actions: read
17+
contents: read # only needed for private repos
18+
actions: read # only needed for private repos
1819
steps:
1920
- name: Checkout repository
20-
uses: actions/checkout@v4
21+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2122
with:
2223
persist-credentials: false
2324

2425
- name: Install the latest version of uv
25-
uses: astral-sh/setup-uv@v5
26+
uses: astral-sh/setup-uv@6b9c6063abd6010835644d4c2e1bef4cf5cd0fca # v6.0.1
2627

2728
- name: Run zizmor 🌈
28-
run: uvx zizmor --format sarif . > results.sarif
29+
run: uvx zizmor --format=sarif . > results.sarif
2930
env:
30-
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
31+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
3132

3233
- name: Upload SARIF file
33-
uses: github/codeql-action/upload-sarif@v3
34+
uses: github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
3435
with:
3536
sarif_file: results.sarif
3637
category: zizmor

0 commit comments

Comments
 (0)