mise-action/.github/workflows
jdx 350683121f
ci(zizmor): scope push trigger and disable advanced-security
Address review feedback on PR #471.

- Add paths filter to the push trigger so the job only runs when
  workflow files change on main (matches the pull_request trigger).
- Set advanced-security: false on zizmor-action. With the default
  true, the action runs codeql-action/upload-sarif which needs
  security-events: write — the job only grants contents: read.
  Disabling it also makes zizmor's exit code drive CI failure,
  matching the "fails CI on any finding" intent.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 13:51:59 -05:00
..
check-dist.yml chore: migrate package manager from npm/pnpm/bun to aube (#455) 2026-04-29 09:13:34 -05:00
ci.yml chore: migrate package manager from npm/pnpm/bun to aube (#455) 2026-04-29 09:13:34 -05:00
codeql-analysis.yml chore(deps): update github/codeql-action digest to 68bde55 (#462) 2026-05-08 05:29:48 +00:00
pr-closer.yml ci: add workflow to auto-close stale PRs (#409) 2026-03-22 11:02:34 -05:00
release-plz.yml chore(deps): update jdx/mise-action action to v4 (#431) 2026-04-10 17:46:00 +00:00
release.yml chore(deps): update jdx/mise-action action to v4 (#431) 2026-04-10 17:46:00 +00:00
test-redacted-env.yml chore(deps): update actions/checkout digest to de0fac2 (#374) 2026-02-06 07:26:12 -06:00
test.yml chore(ci): use !cancelled() instead of always() for final job (#460) 2026-05-03 10:27:10 -05:00
zizmor.yml ci(zizmor): scope push trigger and disable advanced-security 2026-05-12 13:51:59 -05:00