Skip to content

ci: add zizmor security linting#313

Merged
eifinger merged 1 commit intoastral-sh:mainfrom
eifinger-bot:add-zizmor
Jan 30, 2026
Merged

ci: add zizmor security linting#313
eifinger merged 1 commit intoastral-sh:mainfrom
eifinger-bot:add-zizmor

Conversation

@eifinger-bot
Copy link
Contributor

Summary

Adds zizmor security linting to the CI workflow to scan GitHub Actions workflows for security issues.

Changes

  • Added permissions: security-events: write to the lint job (required for zizmor)
  • Added zizmorcore/zizmor-action@v0.4.1 step after actionlint

Mirrors the setup in astral-sh/setup-uv.

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

Add zizmor to the lint job to scan workflows for security issues.
Mirrors the setup in astral-sh/setup-uv.
@eifinger eifinger added the ci Changes to automatic workflows label Jan 30, 2026
@eifinger eifinger enabled auto-merge (squash) January 30, 2026 18:36
@eifinger eifinger merged commit 1977806 into astral-sh:main Jan 30, 2026
66 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Changes to automatic workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants