We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent a1809db commit 1374762Copy full SHA for 1374762
.github/workflows/zizmor.yml
@@ -0,0 +1,21 @@
1
+name: GitHub Actions Security Analysis with zizmor 🌈
2
+
3
+on:
4
+ push:
5
+ branches: ["master"]
6
+ pull_request:
7
+ branches: ["**"]
8
9
+jobs:
10
+ zizmor:
11
+ name: zizmor latest via Cargo
12
+ runs-on: ubuntu-latest
13
+ permissions:
14
+ security-events: write
15
+ steps:
16
+ - name: Checkout repository
17
+ uses: actions/checkout@v6
18
+ with:
19
+ persist-credentials: false
20
+ - name: Run zizmor 🌈
21
+ uses: zizmorcore/zizmor-action@135698455da5c3b3e55f73f4419e481ab68cdd95 # v0.4.1
.github/zizmor.yml
@@ -0,0 +1,7 @@
+rules:
+ unpinned-uses:
+ config:
+ policies:
+ actions/*: ref-pin
+ mongodb-labs/drivers-github-tools/*: ref-pin
+ mongodb-labs/drivers-evergreen-tools: ref-pin
0 commit comments