Skip to content

chore(deps): update quay.io/brancz/kube-rbac-proxy docker tag to v0.2… #2508

chore(deps): update quay.io/brancz/kube-rbac-proxy docker tag to v0.2…

chore(deps): update quay.io/brancz/kube-rbac-proxy docker tag to v0.2… #2508

Workflow file for this run

name: zizmor
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
jobs:
zizmor:
name: GitHub Actions Security Analysis
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write # Required for SARIF upload
actions: read
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Run zizmor
id: zizmor
uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
- name: Check for findings
run: |
findings=$(jq '[.runs[].results[]] | length' "$SARIF")
if [ "$findings" -gt 0 ]; then
echo "::error::zizmor found $findings finding(s)"
exit 1
fi
env:
SARIF: ${{ steps.zizmor.outputs.output-file }}