From 9da886631db59866c87612c3d667c3c1f9f71cba Mon Sep 17 00:00:00 2001 From: Douglas Eichelberger Date: Tue, 29 Sep 2026 12:42:32 -0700 Subject: [PATCH] Use shared-config's reusable zizmor workflow Replaces the copy of the zizmor workflow with a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32), so zizmor-action bumps and fixes land once in shared-config instead of in every repo. It keeps the default advanced-security: true, so results still upload to the Security tab and the same triggers apply. The job no longer requests actions: read, which upload-sarif only needs in private repos. The check is now named "zizmor / zizmor"; no ruleset requires the old name. .github/zizmor.yml still applies: zizmor finds it in the checked-out repo, as before. --- .github/workflows/zizmor.yml | 11 ++--------- 1 file changed, 2 insertions(+), 9 deletions(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index e911917..e5a0721 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -10,14 +10,7 @@ permissions: {} jobs: zizmor: - runs-on: ubuntu-latest permissions: - security-events: write contents: read - actions: read - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Run zizmor - uses: zizmorcore/zizmor-action@6fc4b006235f201fdab3722e17240ab420d580e5 # v0.6.1 + security-events: write + uses: rubyatscale/shared-config/.github/workflows/zizmor.yml@main # zizmor: ignore[unpinned-uses] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically