From baa441c7a0d2d7779c91f7e1fa20a90f4918fd05 Mon Sep 17 00:00:00 2001 From: UW SSEC Bot <154266140+uw-ssec-bot@users.noreply.github.com> Date: Wed, 6 May 2026 22:55:03 +0000 Subject: [PATCH 1/2] ci: adopt zizmor workflow security linting --- .github/workflows/zizmor.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..cba29ca --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,22 @@ +name: Workflow security lint + +on: + pull_request: + branches: [main] + paths: + - ".github/workflows/**" + push: + branches: [main] + paths: + - ".github/workflows/**" + +permissions: {} + +jobs: + lint: + permissions: + contents: read + security-events: write + uses: uw-ssec/.github/.github/workflows/zizmor-lint.yml@main # zizmor: ignore[unpinned-uses] centrally managed org workflow + with: + enforce: false \ No newline at end of file From 3be869777385137e092d3f3a38cc6e139cad0d49 Mon Sep 17 00:00:00 2001 From: UW SSEC Bot <154266140+uw-ssec-bot@users.noreply.github.com> Date: Wed, 6 May 2026 16:16:30 -0700 Subject: [PATCH 2/2] fix: add missing trailing newline to zizmor.yml --- .github/workflows/zizmor.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index cba29ca..a1f13ec 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -19,4 +19,4 @@ jobs: security-events: write uses: uw-ssec/.github/.github/workflows/zizmor-lint.yml@main # zizmor: ignore[unpinned-uses] centrally managed org workflow with: - enforce: false \ No newline at end of file + enforce: false