summaryrefslogtreecommitdiff
path: root/zizmor.yml
diff options
context:
space:
mode:
authorJacob Walls <jacobtylerwalls@gmail.com>2026-04-10 08:21:46 -0400
committernessita <124304+nessita@users.noreply.github.com>2026-04-13 13:04:48 -0300
commitf0b75f46fd0ee98c10887b3c5dc4593d2bccf821 (patch)
treee051477a2d4d1c1ba6247fa619e5bea18c00efa5 /zizmor.yml
parent746f5fd23e50589ef3ad27b1dad46b569f600fa0 (diff)
Removed unused code checkout step from labels.yml GitHub Action.
Diffstat (limited to 'zizmor.yml')
-rw-r--r--zizmor.yml2
1 files changed, 2 insertions, 0 deletions
diff --git a/zizmor.yml b/zizmor.yml
index 23630337b4..19493ba151 100644
--- a/zizmor.yml
+++ b/zizmor.yml
@@ -1,5 +1,7 @@
rules:
dangerous-triggers:
+ # Before ignoring a file, assume all inputs are malicious, assign explicit
+ # minimal permissions, and do not use actions/checkout.
ignore:
- coverage_comment.yml
- labels.yml