👷(ci) add Menshen scan for GitHub Actions vulnerabilities

Wire Menshen into the CI to scan the GitHub Actions we use and flag
vulnerable ones, following the same approach as other projects that
recently adopted it.

Note: I am not fully sure about the current setup. Reviewers should
feel free to adjust the configuration or the integration point as
they see fit.
This commit is contained in:
lebaudantoine
2026-09-28 16:18:22 +02:00
committed by aleb_the_flash
parent 262b168414
commit f172c5795e
2 changed files with 26 additions and 0 deletions
+21
View File
@@ -0,0 +1,21 @@
name: Security analysis
on:
push:
branches:
- main
pull_request:
branches:
- "**"
permissions: {}
jobs:
zizmor:
permissions:
contents: read
actions: read
security-events: write
uses: suitenumerique/ci/.github/workflows/_zizmor.yml@main
with:
config: .github/zizmor.yml