* feat: add prek pre-commit hooks and dependabot Pre-commit hooks (via prek): - Basic hygiene: trailing-whitespace, end-of-file-fixer, check-yaml, check-added-large-files, check-merge-conflict - Security: detect-secrets, zizmor (GitHub Actions audit) - Linting: shellcheck, actionlint, oxlint, swiftlint - Formatting: oxfmt, swiftformat Dependabot: - npm and GitHub Actions ecosystems - Grouped updates (production/development/actions) - 7-day cooldown for supply chain protection Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * docs: add prek install instruction to AGENTS.md --------- Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
18 lines
524 B
YAML
18 lines
524 B
YAML
# zizmor configuration
|
|
# https://docs.zizmor.sh/configuration/
|
|
|
|
rules:
|
|
# Disable unpinned-uses - pinning to SHA hashes is a significant change
|
|
# that should be done deliberately, not enforced by pre-commit
|
|
unpinned-uses:
|
|
disable: true
|
|
|
|
# Disable excessive-permissions for now - adding explicit permissions
|
|
# blocks requires careful review of each workflow's needs
|
|
excessive-permissions:
|
|
disable: true
|
|
|
|
# Disable artipacked (persist-credentials) - low confidence finding
|
|
artipacked:
|
|
disable: true
|