Skip to content

chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group across 1 directory - #1865

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-8280b51821
Open

chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group across 1 directory#1865
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-8280b51821

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 1 update in the / directory: zizmorcore/zizmor-action.

Updates zizmorcore/zizmor-action from 0.6.2 to 0.6.3

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.3

zizmor 1.30.0 is now the default version.

Release notes: zizmorcore/zizmor-action#1300

Commits
  • 70fb788 Sync zizmor versions (#162)
  • 7999d8c chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...
  • 2ae1ce9 chore(deps): bump github/codeql-action/upload-sarif (#160)
  • 951a5ee Skip prerelease versions in sync-zizmor-versions workflow (#158)
  • 79f0191 chore(deps): bump github/codeql-action/upload-sarif (#156)
  • 26a3ae6 sync-zizmor-versions: retry up to 5 times (#155)
  • 435cb31 chore(deps): bump github/codeql-action/upload-sarif (#151)
  • d6cec10 Try the new self-referencing syntax (#148)
  • edd9b84 README: bump pins (#150)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 7, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 7, 2026 06:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 7, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, straightforward dependency version bump.

What was reviewed: the single-line change updating the pinned commit SHA (and version comment) for zizmorcore/zizmor-action from v0.6.2 to v0.6.3 in .github/workflows/zizmor.yml. Confirmed the SHA and comment are consistent, and no other workflow logic, permissions, or triggers were touched.

Extended reasoning...

Overview

The change is a one-line diff in .github/workflows/zizmor.yml, a Dependabot-authored bump of the pinned commit SHA (with matching version comment) for the third-party zizmorcore/zizmor-action from 3dc1ecc... (v0.6.2) to 70fb788... (v0.6.3). No other workflow steps, permissions, triggers, or job configuration changed.

Security risks

None of significance. The action remains pinned to a full commit SHA (not a mutable tag), which is the recommended secure pattern for GitHub Actions and avoids supply-chain risk from tag mutation. The referenced commit is the standard zizmor-action release commit matching the version comment.

Level of scrutiny

Low. This is exactly the kind of mechanical, low-risk change (Dependabot version bump with SHA pinning preserved) that does not require deep review — it doesn't touch permissions, secrets, triggers, or any application code.

Other factors

No CODEOWNERS restriction found for this path in this review context, no outstanding review comments to address, and the bug-hunting system reported no findings.

Bumps the github-actions group with 1 update in the / directory: [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).


Updates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@3dc1ecc...70fb788)

---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group across 1 directory Sep 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-8280b51821 branch from d87ff2e to b4213d6 Compare September 8, 2026 05:55

@wochinge wochinge left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved: pinned GitHub Action patch update reviewed; no workflow logic or permissions changed. The remaining failures are unrelated live-provider OpenAI spend-limit errors.

@wochinge

wochinge commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

@hassiebp I think we have the same spend limit issue here as in the langfuse repository. Can you replace the key?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant