diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000000..37fe3fad56 --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,5 @@ +rules: + unpinned-uses: + config: + policies: + Homebrew/actions/*: ref-pin