From b85f588d57682b43b5d58429de2118464c44e39c Mon Sep 17 00:00:00 2001 From: Douglas Eichelberger Date: Tue, 29 Sep 2026 12:42:32 -0700 Subject: [PATCH] Use shared-config's reusable zizmor workflow Replaces the copy of the zizmor workflow with a caller of rubyatscale/shared-config/.github/workflows/zizmor.yml@main (rubyatscale/shared-config#32), so zizmor-action bumps and fixes land once in shared-config instead of in every repo. It keeps the default advanced-security: true, so results still upload to the Security tab and the same triggers apply. The job no longer requests actions: read, which upload-sarif only needs in private repos. The check is now named "zizmor / zizmor"; no ruleset requires the old name. --- .github/workflows/zizmor.yml | 11 ++--------- 1 file changed, 2 insertions(+), 9 deletions(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 8735b5c..e5a0721 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -10,14 +10,7 @@ permissions: {} jobs: zizmor: - runs-on: ubuntu-latest permissions: - security-events: write contents: read - actions: read - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Run zizmor - uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 + security-events: write + uses: rubyatscale/shared-config/.github/workflows/zizmor.yml@main # zizmor: ignore[unpinned-uses] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically