Skip to content

chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group across 1 directory - #1865

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-8280b51821
Open

chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group across 1 directory#1865
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-8280b51821

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 1 update in the / directory: zizmorcore/zizmor-action.

Updates zizmorcore/zizmor-action from 0.6.2 to 0.6.3

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.3

zizmor 1.30.0 is now the default version.

Release notes: zizmorcore/zizmor-action#1300

Commits
  • 70fb788 Sync zizmor versions (#162)
  • 7999d8c chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...
  • 2ae1ce9 chore(deps): bump github/codeql-action/upload-sarif (#160)
  • 951a5ee Skip prerelease versions in sync-zizmor-versions workflow (#158)
  • 79f0191 chore(deps): bump github/codeql-action/upload-sarif (#156)
  • 26a3ae6 sync-zizmor-versions: retry up to 5 times (#155)
  • 435cb31 chore(deps): bump github/codeql-action/upload-sarif (#151)
  • d6cec10 Try the new self-referencing syntax (#148)
  • edd9b84 README: bump pins (#150)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 7, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 7, 2026 06:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 7, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, straightforward dependency version bump.

What was reviewed: the single-line change updating the pinned commit SHA (and version comment) for zizmorcore/zizmor-action from v0.6.2 to v0.6.3 in .github/workflows/zizmor.yml. Confirmed the SHA and comment are consistent, and no other workflow logic, permissions, or triggers were touched.

Extended reasoning...

Overview

The change is a one-line diff in .github/workflows/zizmor.yml, a Dependabot-authored bump of the pinned commit SHA (with matching version comment) for the third-party zizmorcore/zizmor-action from 3dc1ecc... (v0.6.2) to 70fb788... (v0.6.3). No other workflow steps, permissions, triggers, or job configuration changed.

Security risks

None of significance. The action remains pinned to a full commit SHA (not a mutable tag), which is the recommended secure pattern for GitHub Actions and avoids supply-chain risk from tag mutation. The referenced commit is the standard zizmor-action release commit matching the version comment.

Level of scrutiny

Low. This is exactly the kind of mechanical, low-risk change (Dependabot version bump with SHA pinning preserved) that does not require deep review — it doesn't touch permissions, secrets, triggers, or any application code.

Other factors

No CODEOWNERS restriction found for this path in this review context, no outstanding review comments to address, and the bug-hunting system reported no findings.

Bumps the github-actions group with 1 update in the / directory: [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).


Updates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@3dc1ecc...70fb788)

---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group across 1 directory Sep 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-8280b51821 branch from d87ff2e to b4213d6 Compare September 8, 2026 05:55

@wochinge wochinge left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved: pinned GitHub Action patch update reviewed; no workflow logic or permissions changed. The remaining failures are unrelated live-provider OpenAI spend-limit errors.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant