Build(deps): Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 - #845
Conversation
Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.7 to 0.6.0. - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](zizmorcore/zizmor-action@192e21d...6599ee8) --- updated-dependencies: - dependency-name: zizmorcore/zizmor-action dependency-version: 0.6.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
⏸️ Hold — Bot PR Safety Review
Recommendation: Wait until 2026-07-29 for the 7-day cooldown to elapse, then verify tag integrity manually before merging. No other concerns. This review comment was generated by an agent. It is advisory only and does not approve or merge the PR. Reviewed on 2026-07-22 16:42 UTC. |
Bot PR review — zizmorcore/zizmor-action 0.5.7 → 0.6.0Recommendation: ✅ Merge — cooldown honored, tag verified, the Cooldown: honored. v0.6.0 released 2026-07-15, PR opened 07-22 = 7 days. Security: CI-only security linter, not shipped to users. No known advisories against v0.6.0. Risk: Low. A 0.5 → 0.6 minor of the linter could surface new findings, but Tag integrity: SHA CI: all green. This review comment was generated by Claude (Claude Code). It is advisory only and does not approve or merge the PR. Reviewed on 2026-07-27 10:27 UTC. |
Bumps zizmorcore/zizmor-action from 0.5.7 to 0.6.0.
Release notes
Sourced from zizmorcore/zizmor-action's releases.
Commits
6599ee8Addcollectinput (#139)bec05c8Sync zizmor versions (#137)cf59549Add issue templates (#135)f72bf17chore(deps): bump github/codeql-action/upload-sarif (#134)b2a6facci: block version sync workflow on forks (#129)2d88f44Readme: document missing inputs (#130)d81e276Fold Docker image pull output into a collapsed Actions log group (#132)8c13c53chore(deps): bump the github-actions group with 2 updates (#133)2f8e9c6README: bump versions (#128)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)