Skip to content

chore: Fix GitHub Actions findings with zizmor#107

Merged
Pavel Zwerschke (pavelzw) merged 1 commit intomainfrom
zizmor-fixes
Apr 4, 2026
Merged

chore: Fix GitHub Actions findings with zizmor#107
Pavel Zwerschke (pavelzw) merged 1 commit intomainfrom
zizmor-fixes

Conversation

@quant-ranger
Copy link
Copy Markdown
Contributor

@quant-ranger quant-ranger bot commented Apr 4, 2026

This PR automatically fixes findings in GitHub Actions workflows using zizmor.

The following rules are enabled:

  • ref-version-mismatch: A ref-version-mismatch occurs when an action is hash-pinned but the associated tag comment (e.g. # v3.8.1) does not match the pinned commit. This can cause tools like Dependabot to silently ignore the comment instead of refreshing it.
  • dependabot-cooldown: Ensures that dependabot configurations include a cooldown period.

If you run into any problems, feel free to ping Yannik Tausch (@ytausch) or Manuel Lerchner (@ManuelLerchnerQC).

@pavelzw Pavel Zwerschke (pavelzw) merged commit 8264bd6 into main Apr 4, 2026
18 checks passed
@pavelzw Pavel Zwerschke (pavelzw) deleted the zizmor-fixes branch April 4, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant