Skip to content

Commit 6dfae22

Browse files
authored
Merge pull request #277 from maxmind/wstorey/eng-3188-zizmor-github-action-does-not-depend-on-astral-shsetup-uv
Run zizmor via zizmorcore/zizmor-action
2 parents 5720839 + ec1311f commit 6dfae22

File tree

1 file changed

+3
-12
lines changed

1 file changed

+3
-12
lines changed

.github/workflows/zizmor.yml

Lines changed: 3 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -6,27 +6,18 @@ on:
66
pull_request:
77
branches: ["**"]
88

9+
permissions: {}
10+
911
jobs:
1012
zizmor:
11-
name: zizmor latest via PyPI
1213
runs-on: ubuntu-latest
1314
permissions:
1415
security-events: write
15-
# required for workflows in private repositories
16-
contents: read
17-
actions: read
1816
steps:
1917
- name: Checkout repository
2018
uses: actions/checkout@v5
2119
with:
2220
persist-credentials: false
2321

24-
- name: Install the latest version of uv
25-
uses: astral-sh/setup-uv@eb1897b8dc4b5d5bfe39a428a8f2304605e0983c # 7.0.0
26-
with:
27-
enable-cache: false
28-
2922
- name: Run zizmor
30-
run: uvx zizmor@1.13.0 --format plain .
31-
env:
32-
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
23+
uses: zizmorcore/zizmor-action@e673c3917a1aef3c65c972347ed84ccd013ecda4 # v0.2.0

0 commit comments

Comments
 (0)