name: Zizmor on: push: branches: - main paths: - '.github/workflows/**' pull_request: branches: - main paths: - '.github/workflows/**' workflow_dispatch: jobs: zizmor: runs-on: ubuntu-latest permissions: contents: read security-events: write steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Run zizmor uses: zizmorcore/zizmor-action@a16621b09c6db4281f81a93cb393b05dcd7b7165 # v0.5.5