summaryrefslogtreecommitdiff
path: root/zizmor.yml
blob: 5bf79eb8cc054d62a6caec938c8aa776a51cd467 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
rules:
  dangerous-triggers:
    # Before ignoring a file, assume all inputs are malicious, assign explicit
    # minimal permissions, and do not use actions/checkout.
    ignore:
      - labels.yml
      - new_contributor_pr.yml
  unpinned-uses:
    config:
      policies:
        actions/*: ref-pin
        psf/*: ref-pin