From f172c5795e44c8423a9e0ae552daa3e968eda18b Mon Sep 17 00:00:00 2001 From: lebaudantoine Date: Mon, 28 Sep 2026 16:18:22 +0200 Subject: [PATCH] =?UTF-8?q?=F0=9F=91=B7(ci)=20add=20Menshen=20scan=20for?= =?UTF-8?q?=20GitHub=20Actions=20vulnerabilities?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Wire Menshen into the CI to scan the GitHub Actions we use and flag vulnerable ones, following the same approach as other projects that recently adopted it. Note: I am not fully sure about the current setup. Reviewers should feel free to adjust the configuration or the integration point as they see fit. --- .github/workflows/security.yml | 21 +++++++++++++++++++++ .github/zizmor.yml | 5 +++++ 2 files changed, 26 insertions(+) create mode 100644 .github/workflows/security.yml create mode 100644 .github/zizmor.yml diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 00000000..e43a2aa3 --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,21 @@ +name: Security analysis + +on: + push: + branches: + - main + pull_request: + branches: + - "**" + +permissions: {} + +jobs: + zizmor: + permissions: + contents: read + actions: read + security-events: write + uses: suitenumerique/ci/.github/workflows/_zizmor.yml@main + with: + config: .github/zizmor.yml diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 00000000..863510c2 --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,5 @@ +rules: + unpinned-uses: + config: + policies: + "suitenumerique/*": ref-pin