Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency zizmor to v1.3.1 #1261

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jan 25, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
zizmor 1.2.1 -> 1.3.1 age adoption passing confidence

Release Notes

woodruffw/zizmor (zizmor)

v1.3.1

Compare Source

Improvements 🌱🔗

  • Passing both --offline and a GitHub token (either implicitly with GH_TOKEN or explicitly with --gh-token) no longer results in an error. --offline is now given precedence, regardless of any other flags or environment settings (#​519)

Bug Fixes 🐛🔗

  • Fixed a bug where zizmor would fail to parse composite actions with inputs/outputs that are missing descriptions (#​502)
  • Expressions that contain indices with non-semantic whitespace are now parsed correctly (#​511)
  • Fixed a false positive in [ref-confusion] where partial tag matches were incorrectly considered confusable (#​519)
  • Fixed a bug where zizmor would fail to parse workflow definitions with an expression inside strategy.max-parallel (#​522)

v1.3.0

Compare Source

This release comes with one new audit (overprovisioned-secrets), plus a handful of bugfixes and analysis improvements to existing audits. It also comes with a special easter egg for those who wish to kvell about their audit results.

New Features 🌈🔗

  • New audit: overprovisioned-secrets detects uses of the secrets context that result in excessive secret provisioning (#​485)
  • Added a special naches mode for when you're feeling particularly proud of your audit results (#​490)

Improvements 🌱🔗

  • zizmor produces slightly more informative error messages when given an invalid input file (#​482)
  • Case insensitivity in contexts is now handeled more consistently and pervasively (#​491)

Bug Fixes 🐛🔗

  • Fixed a bug where zizmor would fail to discover actions within subdirectories of .github/workflows (#​477)
  • Fixed a bug where zizmor would fail to parse composite action definitions with no name field (#​487)

v1.2.2

Compare Source

Bug Fixes 🐛🔗

Improvements 🌱🔗

  • Fetch failures when running zizmor org/repo are now more informative (#​475)

Configuration

📅 Schedule: Branch creation - "* * * * 0,6" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Python Dependencies label Jan 25, 2025
@renovate renovate bot requested a review from edgarrmondragon as a code owner January 25, 2025 19:14
@renovate renovate bot force-pushed the renovate/zizmor-1.x branch from b17985c to 12e1a23 Compare January 25, 2025 19:52
@renovate renovate bot force-pushed the renovate/zizmor-1.x branch 4 times, most recently from 4df6411 to 3d297aa Compare January 26, 2025 04:11
@renovate renovate bot force-pushed the renovate/zizmor-1.x branch from 3d297aa to 1e59d73 Compare January 29, 2025 01:43
@renovate renovate bot changed the title chore(deps): update dependency zizmor to v1.2.2 chore(deps): update dependency zizmor to v1.3.0 Jan 29, 2025
@edgarrmondragon edgarrmondragon self-assigned this Jan 29, 2025
@renovate renovate bot force-pushed the renovate/zizmor-1.x branch 3 times, most recently from 6397f2c to d46917e Compare February 1, 2025 03:00
@renovate renovate bot force-pushed the renovate/zizmor-1.x branch from d46917e to c975384 Compare February 9, 2025 17:30
@renovate renovate bot changed the title chore(deps): update dependency zizmor to v1.3.0 chore(deps): update dependency zizmor to v1.3.1 Feb 9, 2025
Copy link

sonarqubecloud bot commented Feb 9, 2025

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Python Dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant