From 452e06882af4d6dcfdb1b95524dec6e4f20240a0 Mon Sep 17 00:00:00 2001 From: Douglas Eichelberger Date: Tue, 29 Sep 2026 12:42:33 -0700 Subject: [PATCH] Use shared-config's reusable zizmor workflow Replaces the copy of the zizmor workflow with a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32), so zizmor-action bumps and fixes land once in shared-config instead of in every repo. It keeps the default advanced-security: true, so results still upload to the Security tab and the same triggers apply. The job no longer requests actions: read, which upload-sarif only needs in private repos. The check is now named "zizmor / zizmor"; no ruleset requires the old name. This moves zizmor-action from v0.6.3 to v0.6.4, the version shared-config pins. --- .github/workflows/zizmor.yml | 15 +++------------ 1 file changed, 3 insertions(+), 12 deletions(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index c42ea47..6f2ef70 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -2,7 +2,7 @@ name: GitHub Actions Security Analysis with zizmor 🌈 on: push: - branches: ["main"] + branches: [main] pull_request: branches: ["**"] @@ -10,16 +10,7 @@ permissions: {} jobs: zizmor: - runs-on: ubuntu-latest permissions: - security-events: write contents: read - actions: read - steps: - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: Run zizmor 🌈 - uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3 + security-events: write + uses: rubyatscale/shared-config/.github/workflows/zizmor.yml@main # zizmor: ignore[unpinned-uses] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically