From 0ed05a2637b6e28a8254b38406dc28f5d7db11c6 Mon Sep 17 00:00:00 2001 From: UW SSEC Bot <154266140+uw-ssec-bot@users.noreply.github.com> Date: Wed, 6 May 2026 22:57:36 +0000 Subject: [PATCH 1/2] ci: adopt zizmor workflow security linting --- .github/workflows/zizmor.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 .github/workflows/zizmor.yml diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..cba29ca --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,22 @@ +name: Workflow security lint + +on: + pull_request: + branches: [main] + paths: + - ".github/workflows/**" + push: + branches: [main] + paths: + - ".github/workflows/**" + +permissions: {} + +jobs: + lint: + permissions: + contents: read + security-events: write + uses: uw-ssec/.github/.github/workflows/zizmor-lint.yml@main # zizmor: ignore[unpinned-uses] centrally managed org workflow + with: + enforce: false \ No newline at end of file From d2c8111b8d2b3ed368e0cfb58a689b3bc1febe5d Mon Sep 17 00:00:00 2001 From: UW SSEC Bot <154266140+uw-ssec-bot@users.noreply.github.com> Date: Wed, 6 May 2026 16:16:44 -0700 Subject: [PATCH 2/2] fix: add missing trailing newline to zizmor.yml --- .github/workflows/zizmor.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index cba29ca..a1f13ec 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -19,4 +19,4 @@ jobs: security-events: write uses: uw-ssec/.github/.github/workflows/zizmor-lint.yml@main # zizmor: ignore[unpinned-uses] centrally managed org workflow with: - enforce: false \ No newline at end of file + enforce: false