Skip to content

Commit 8eac3fd

Browse files
committed
Run Zizmor from PyPI
Hilariously, because it's faster.
1 parent 2c8b35b commit 8eac3fd

File tree

1 file changed

+8
-7
lines changed

1 file changed

+8
-7
lines changed

.github/workflows/zizmor.yml

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ permissions:
1313

1414
jobs:
1515
zizmor:
16-
name: Zizmor latest via Cargo
16+
name: Zizmor latest via PyPI
1717
runs-on: ubuntu-latest
1818
permissions:
1919
security-events: write
@@ -22,12 +22,13 @@ jobs:
2222
uses: actions/checkout@v4
2323
with:
2424
persist-credentials: false
25-
- name: Setup Rust
26-
uses: actions-rust-lang/setup-rust-toolchain@v1
27-
- name: Get zizmor
28-
run: cargo install zizmor
29-
- name: Run zizmor
30-
run: zizmor --format sarif . > results.sarif
25+
- uses: hynek/setup-cached-uv@v2
26+
27+
- name: Run zizmor 🌈
28+
run: uvx zizmor --format sarif . > results.sarif
29+
env:
30+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
31+
3132
- name: Upload SARIF file
3233
uses: github/codeql-action/upload-sarif@v3
3334
with:

0 commit comments

Comments
 (0)