{"repo":"zizmorcore/zizmor-action","free":true,"listed":false,"github":"https://github.com/zizmorcore/zizmor-action","clone":"git clone https://github.com/zizmorcore/zizmor-action.git","description":"Run zizmor from GitHub Actions!","language":"Shell","stars":153,"topics":["github-actions","static-analysis","zizmor"],"license":"MIT","category":"dev-tools","readme_excerpt":"zizmor-action 🌈 Run [ zizmor ] from GitHub Actions! [!WARNING] This action is ready for public use, but it is still in early development. Please report any issues you encounter, and be aware that backwards incompatible changes may be made until a stable version is released. Table of Contents - Quickstart - Usage with Github Advanced Security (recommended) - Usage without Github Advanced Security - Inputs - inputs - collect - online-audits - persona - min-severity - min-confidence - version - token - advanced-security - annotations - color - config - fail-on-no-inputs - Outputs - Permissions - Troubleshooting Quickstart This section lists a handful of quick-start examples to get you up and running with zizmor and zizmor-action . See the Inputs section for more details on how zizmor-action can be configured. If you run into any issues, please see the Troubleshooting section! Usage with Github Advanced Security (recommended) [!IMPORTANT] This mode requires that your repository is public or that you have [Advanced Security] as a paid feature on your private repository. If neither of these applies to you, you can use zizmor-action with advanced-security: false ; see below for more details. [!IMPORTANT] In this mode, the action will not fail when zizmor produces findings. This is because Advanced Security encourages workflows to only fail on internal errors. To use workflow failure as a blocking signal, you can use GitHub's rulesets feature. For more information, see [Set code sca","default_branch":null,"files":null,"tree":[],"storefront":"/r/zizmorcore","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/zizmorcore/zizmor-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}