-
Notifications
You must be signed in to change notification settings - Fork 66
38 lines (33 loc) · 947 Bytes
/
Copy pathzizmor.yaml
File metadata and controls
38 lines (33 loc) · 947 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
name: zizmor
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
jobs:
zizmor:
name: GitHub Actions Security Analysis
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write # Required for SARIF upload
actions: read
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Run zizmor
id: zizmor
uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3
- name: Check for findings
run: |
findings=$(jq '[.runs[].results[]] | length' "$SARIF")
if [ "$findings" -gt 0 ]; then
echo "::error::zizmor found $findings finding(s)"
exit 1
fi
env:
SARIF: ${{ steps.zizmor.outputs.output-file }}