Skip to content

Commit 30ec0b3

Browse files
ci: Add actionlint and zizmor jobs to lint workflow
- Integrated `actionlint` to check GitHub Actions workflows. - Integrated `zizmor` to run security analysis on workflows and upload SARIF files. Co-authored-by: tswast <247555+tswast@users.noreply.github.com>
1 parent b7ec82f commit 30ec0b3

1 file changed

Lines changed: 29 additions & 1 deletion

File tree

‎.github/workflows/lint.yml‎

Lines changed: 29 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,4 +28,32 @@ jobs:
2828
run: uv sync --locked --all-extras --dev
2929

3030
- name: Run linter
31-
run: uv run ruff check
31+
run: uv run ruff check
32+
actionlint:
33+
name: actionlint
34+
runs-on: ubuntu-latest
35+
steps:
36+
- uses: actions/checkout@v4
37+
- name: Run actionlint
38+
uses: reviewdog/action-actionlint@v1
39+
40+
zizmor:
41+
name: zizmor
42+
runs-on: ubuntu-latest
43+
permissions:
44+
security-events: write
45+
contents: read
46+
actions: read
47+
steps:
48+
- uses: actions/checkout@v4
49+
- name: Install uv
50+
uses: astral-sh/setup-uv@v6
51+
- name: Run zizmor
52+
run: uvx zizmor --format sarif . > results.sarif
53+
env:
54+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
55+
- name: Upload SARIF file
56+
uses: github/codeql-action/upload-sarif@v3
57+
with:
58+
sarif_file: results.sarif
59+
category: zizmor

0 commit comments

Comments
 (0)