Bump zizmorcore/zizmor from 1.18.0 to 1.23.1#24694
Bump zizmorcore/zizmor from 1.18.0 to 1.23.1#24694dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps [zizmorcore/zizmor](https://github.com/zizmorcore/zizmor) from 1.18.0 to 1.23.1. - [Release notes](https://github.com/zizmorcore/zizmor/releases) - [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md) - [Commits](zizmorcore/zizmor@v1.18.0...v1.23.1) --- updated-dependencies: - dependency-name: zizmorcore/zizmor dependency-version: 1.23.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
There seem to have been a number of changes between 1.18 and 1.23 - there are some new rules in particular we are now hitting: The former is probably useful, and can be easily applied (at a cost of more dependabot PRs, this time for action updates); the latter depends on us setting up environments for addons-server, which we either don't have an at org level, or I don't currently have access to. It would also mean redefining all our secrets in an environment, and I suspect we don't have copies of all (any?) of them. |
This is the main difference with before when it comes to pinning
We could consider pinning the built-in ones using hashes too... I suspect they are fairly low traffic anyway... In this repo that'd mean:
|
Bumps zizmorcore/zizmor from 1.18.0 to 1.23.1.
Release notes
Sourced from zizmorcore/zizmor's releases.
... (truncated)
Changelog
Sourced from zizmorcore/zizmor's changelog.
... (truncated)
Commits
0b77258zizmor v1.23.1 (#1725)d822fa6Remove conflict handling from GH_TOKEN aliases (#1724)773439bBump trophies (#1721)f5c05f0zizmor 1.23.0 (#1719)93858d8zizmor 1.23.0-rc7 (#1718)76d3f1eyamlpatch 0.13.0 (#1717)7a71262github-actions-expressions 0.0.15 (#1716)2255be6zizmor 1.23.0-rc6 (#1715)a0f9dcbFix http-cache usage (#1689)adabd2dUpdate pedantic persona example (#1714)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)