From 71017267deeeb48e380132864d3b0b166c8d90d1 Mon Sep 17 00:00:00 2001 From: William Woodruff Date: Sun, 11 May 2025 02:24:57 -0400 Subject: [PATCH] chore(docs): constrain permissions in workflow example (#781) --- .github/workflows/zizmor.yml | 4 ++-- docs/usage.md | 2 ++ 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 84cc7b53..fed35918 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -4,7 +4,7 @@ on: push: branches: ["main"] pull_request: - branches: ["*"] + branches: ["**"] permissions: {} @@ -23,7 +23,7 @@ jobs: - name: Install the latest version of uv uses: astral-sh/setup-uv@6b9c6063abd6010835644d4c2e1bef4cf5cd0fca # v6.0.1 - name: Run zizmor 🌈 - run: uvx zizmor --format sarif .github/workflows > results.sarif + run: uvx zizmor --format sarif . > results.sarif env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Upload SARIF file diff --git a/docs/usage.md b/docs/usage.md index 7f09bd39..c565ea50 100644 --- a/docs/usage.md +++ b/docs/usage.md @@ -566,6 +566,8 @@ two primary ways to use `zizmor` in GitHub Actions: pull_request: branches: ["**"] + permissions: {} + jobs: zizmor: name: zizmor latest via PyPI