Skip to content

Dev setup

Dev setup #11

Workflow file for this run

name: Workflows Audit
on:
push:
branches:
- master
paths:
- '.github/**'
pull_request:
paths:
- '.github/**'
permissions:
contents: read
actions: read
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- name: Run Zizmor audit
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
docker run --rm -v ${{ github.workspace }}:/workspace/ -w /workspace/ ghcr.io/zizmorcore/zizmor@sha256:4d3128ae1370da9507bdd42a62d72b8304d4d0f290147aaac3eb0ebf51d70890 \
-p --gh-token ${GITHUB_TOKEN} .github/workflows/