Skip to content

chore: Fix GitHub Actions findings with zizmor#15

Merged
Oliver Borchert (borchero) merged 1 commit intomainfrom
zizmor-fixes
Apr 11, 2026
Merged

chore: Fix GitHub Actions findings with zizmor#15
Oliver Borchert (borchero) merged 1 commit intomainfrom
zizmor-fixes

Conversation

@quant-ranger
Copy link
Copy Markdown

@quant-ranger quant-ranger Bot commented Apr 11, 2026

This PR automatically fixes findings in GitHub Actions workflows using zizmor.

The following rules are enabled:

  • ref-version-mismatch: A ref-version-mismatch occurs when an action is hash-pinned but the associated tag comment (e.g. # v3.8.1) does not match the pinned commit. This can cause tools like Dependabot to silently ignore the comment instead of refreshing it.
  • dependabot-cooldown: Ensures that dependabot configurations include a cooldown period.

If you run into any problems, feel free to ping Yannik Tausch (@ytausch) or Pavel Zwerschke (@pavelzw).

@borchero Oliver Borchert (borchero) merged commit 6ce8090 into main Apr 11, 2026
9 checks passed
@borchero Oliver Borchert (borchero) deleted the zizmor-fixes branch April 11, 2026 10:49
Oliver Borchert (borchero) added a commit that referenced this pull request Apr 30, 2026
Squashed commits from PRs #15, #16:
- Fix GitHub Actions findings with zizmor (#15)
- Pin GitHub Actions dependencies (#16)
Oliver Borchert (borchero) added a commit that referenced this pull request Apr 30, 2026
Squashed commits from PRs #15, #16:
- Fix GitHub Actions findings with zizmor (#15)
- Pin GitHub Actions dependencies (#16)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant