diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 000000000..a40e4188f --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,6 @@ +rules: + unpinned-uses: + config: + policies: + actions/*: ref-pin + dependabot/*: ref-pin