Skip to content

chore: Fix GitHub Actions findings with zizmor#196

Open
quant-ranger[bot] wants to merge 1 commit intomainfrom
zizmor-fixes
Open

chore: Fix GitHub Actions findings with zizmor#196
quant-ranger[bot] wants to merge 1 commit intomainfrom
zizmor-fixes

Conversation

@quant-ranger
Copy link
Copy Markdown
Contributor

@quant-ranger quant-ranger bot commented Apr 4, 2026

This PR automatically fixes findings in GitHub Actions workflows using zizmor.

The following rules are enabled:

  • ref-version-mismatch: A ref-version-mismatch occurs when an action is hash-pinned but the associated tag comment (e.g. # v3.8.1) does not match the pinned commit. This can cause tools like Dependabot to silently ignore the comment instead of refreshing it.
  • dependabot-cooldown: Ensures that dependabot configurations include a cooldown period.

If you run into any problems, feel free to ping Yannik Tausch (@ytausch) or Pavel Zwerschke (@pavelzw).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants