Skip to content

chore(deps): update dependency pipx:zizmor to v1.24.1#165

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/pipx-zizmor-1.x
Open

chore(deps): update dependency pipx:zizmor to v1.24.1#165
renovate[bot] wants to merge 1 commit intomainfrom
renovate/pipx-zizmor-1.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Sep 16, 2025

This PR contains the following updates:

Package Change Age Confidence
pipx:zizmor (source) 1.23.11.24.1 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

zizmorcore/zizmor (pipx:zizmor)

v1.24.1

Compare Source

Bug Fixes 🐛🔗
  • Fixed a bug where the ref-version-mismatch audit would incorrectly flag some version comments as not containing an appropriate version (#​1900)

v1.24.0

Compare Source

New Features 🌈🔗
  • zizmor now allows users to audit from stdin, by passing zizmor - (#​1611)
Enhancements 🌱🔗
Bug Fixes 🐛🔗
  • Fixed a bug where the concurrency-limits audit reported findings at the job level instead of the workflow level (#​1627)

  • Fixed a bug where with: ${{ expr }} clauses would cause a crash. artipacked audit emits a pedantic finding on such clauses. (#​1772)

  • Fixed a bug where auto-fixes for the template-injection audit would fail to preserve an environment variable's casing (#​1766)

  • Fixed a bug where the secrets-outside-env audit would incorrectly flag reusable workflows (#​1777)

  • Fixed a bug where expressions containing Infinity or NaN would fail to parse (#​1778)

  • Fixed several bugs where some parenthetical forms in expressions would fail to parse (#​1779, #​1856)

  • Fixed a bug where expressions with invalid identifiers (such as -Inf) would be incorrectly accepted (#​1794)

  • Fixed a bug where the known-vulnerable-actions audit would fail to handle multiple discrete packages in a single advisory (#​1810)

  • Fixed a bug where the template-injection audit would incorrectly flag needs.*.result as an injection risk in the default persona (#​1814)

  • Fixed a bug where the unpinned-uses audit would product incorrect auto-fixes for actions with subpaths (#​1841)

  • Fixed a bug where the ref-version-mismatch audit would fail to produce findings for comments containing nonexistent refs (#​1853)

  • Fixed a bug where expressions containing NaN would be constant-evaluated incorrectly (#​1858)

  • Fixed a bug where nix would not be recognized as a package-ecosystem in dependabot.yml (#​1867)

  • Fixed a bug where the ref-version-mismatch audit would incorrectly parse prerelease version comments (such as # v6-beta), causing some findings to appear unresolvable (#​1870)

  • Fixed a bug where various string comparisons in expressions did not perfectly match GitHub's own special uppercasing semantics (#​1879)

  • Fixed a bug where zizmor would incorrectly contact github.com instead of the user's requested --gh-hostname for some online requests (#​1874)

  • Fixed a bug where the artipacked audit would fail to honor the --no-online-audits flag (#​1874)

Changes ⚠️🔗
  • The secrets-outside-env audit now only flags findings with the 'auditor' persona, due to numerous false positives and negatives caused by GitHub's platform limitations (primarily around interactions between environment secrets and reusable workflows) (#​1777)

  • zizmor's handling of GitHub Actions expressions has been made stricter, and now rejects unknown functions and function calls with incorrect arities (#​1823, #​1826)

  • The superfluous-actions audit now uses the "pedantic" persona for some findings along with a medium or low confidence marker to signal when a action may not be easily replaced with built-in functionality (#​1822, #​1859)

  • The unpinned-uses audit no longer suggests auto-fixes for Git references that don't look like version tags, such as main (#​1860)

  • The template-injection audit now considers more "URL-shaped" contexts to be fully attacker-controllable, rather than partially controllable (#​1868)


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the renovate label Sep 16, 2025
@renovate renovate Bot requested a review from ryo246912 September 16, 2025 04:45
@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Sep 16, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate renovate Bot force-pushed the renovate/pipx-zizmor-1.x branch 18 times, most recently from 7e84eac to 9d43752 Compare September 22, 2025 13:55
@renovate renovate Bot force-pushed the renovate/pipx-zizmor-1.x branch 9 times, most recently from 579040a to dc303fe Compare September 25, 2025 15:01
@renovate renovate Bot force-pushed the renovate/pipx-zizmor-1.x branch from 07e3f35 to 59a2f8c Compare September 29, 2025 17:07
@renovate renovate Bot changed the title chore(deps): update dependency pipx:zizmor to v1.13.0 chore(deps): update dependency pipx:zizmor to v1.14.0 Sep 29, 2025
@renovate renovate Bot changed the title chore(deps): update dependency pipx:zizmor to v1.14.0 chore(deps): update dependency pipx:zizmor to v1.14.1 Sep 29, 2025
@renovate renovate Bot force-pushed the renovate/pipx-zizmor-1.x branch 6 times, most recently from af21b90 to 6148d45 Compare October 2, 2025 17:21
@renovate renovate Bot changed the title chore(deps): update dependency pipx:zizmor to v1.14.1 chore(deps): update dependency pipx:zizmor to v1.14.2 Oct 2, 2025
@renovate renovate Bot force-pushed the renovate/pipx-zizmor-1.x branch 17 times, most recently from 7037c10 to be0ad1f Compare October 9, 2025 14:22
@renovate renovate Bot force-pushed the renovate/pipx-zizmor-1.x branch 2 times, most recently from 5075c12 to f6b094a Compare October 10, 2025 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant