mise-action/.github
jdx 350683121f
ci(zizmor): scope push trigger and disable advanced-security
Address review feedback on PR #471.

- Add paths filter to the push trigger so the job only runs when
  workflow files change on main (matches the pull_request trigger).
- Set advanced-security: false on zizmor-action. With the default
  true, the action runs codeql-action/upload-sarif which needs
  security-events: write — the job only grants contents: read.
  Disabling it also makes zizmor's exit code drive CI failure,
  matching the "fails CI on any finding" intent.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 13:51:59 -05:00
..
linters feat: support windows (#122) 2024-09-25 21:27:52 +00:00
workflows ci(zizmor): scope push trigger and disable advanced-security 2026-05-12 13:51:59 -05:00
renovate.json feat: use autofix.ci to auto-update dist/ on all PRs 2025-10-31 09:43:48 -05:00