Skip to content

chore(deps): update pre-commit hook zizmorcore/zizmor-pre-commit to v1.30.0 - #85

Merged
JohnStrunk merged 1 commit into
mainfrom
renovate/zizmorcore-zizmor-pre-commit-1.x
Sep 10, 2026
Merged

JohnStrunk merged 1 commit into
mainfrom
renovate/zizmorcore-zizmor-pre-commit-1.x

Conversation

@hermes-renovate

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending
zizmorcore/zizmor-pre-commit repository minor v1.29.0v1.30.0 v1.30.1

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

zizmorcore/zizmor-pre-commit (zizmorcore/zizmor-pre-commit)

v1.30.0

Compare Source

Sponsorship is appreciated!

New Features 🌈🔗

Bug Fixes 🐛🔗

  • Fixed a bug where zizmor would reject a .pre-commit-config.yml input containing a prek-specific builtin section (#​2259)

  • Fixed a bug where the unpinned-uses audit would fail to honor ignore comments within the same step scope (#​2289)

  • Fixed a bug where zizmor would reject a dependabot.yml containing a goproxy-server registry definition (#​2300)

  • Fixed a bug where zizmor would reject pre-commit configurations containing prek-specific glob patterns in files or exclude (#​2308)

  • Fixed a handful of unsound patch bugs when performing YAML add and/or replace operations (#​2295)

    Many thanks to @​dmbuil for proposing and implementing this improvement!

  • Fixed a bug where the cache-poisoning audit would incorrectly flag newer astral-sh/setup-uv versions that disable caching behavior automatically (#​2330)

  • Fixed a bug where the ref-version-mismatch audit would produce a misleading diagnostic when an action has overlapping branch and tag names (#​2337)

  • Fixed a bug where the artipacked audit would incorrectly flag the with: clauses of unrelated actions (#​2339)

  • Fixed a class of bugs where zizmor would incorrectly match an action's commit to a sibling action's tag (#​2247)

    Many thanks to @​potiuk for proposing and implementing this improvement!

  • Fixed a bug where zizmor would crash on deeply nested GitHub Actions expressions (#​2349)


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

…1.30.0

Signed-off-by: hermes-renovate[bot] <286339580+hermes-renovate[bot]@users.noreply.github.com>
@hermes-renovate
hermes-renovate Bot requested a review from a team September 9, 2026 21:48
@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 7d0bfa20-3d56-4e03-9261-2752df6691c0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@JohnStrunk
JohnStrunk added this pull request to the merge queue Sep 10, 2026
Merged via the queue into main with commit c9f097b Sep 10, 2026
17 checks passed
@JohnStrunk
JohnStrunk deleted the renovate/zizmorcore-zizmor-pre-commit-1.x branch September 10, 2026 16:08
@fullsend-ai-retro

Copy link
Copy Markdown

PR #85 is a straightforward Renovate bot dependency bump — updating zizmorcore/zizmor-pre-commit from v1.29.0 to v1.30.0 in .pre-commit-config.yaml (1 line changed). No fullsend code, review, fix, or triage agents were dispatched. CodeRabbit skipped review (bot author detected). JohnStrunk approved without comments and the PR merged ~18 hours after creation.

The only agent involvement was this retro dispatch, triggered on merge. Since there was zero prior agent activity to retrospect on, this retro run produced no actionable findings — it is pure overhead.

This scenario — retro dispatching on bot-authored PRs with no agent involvement — is already well-covered by existing upstream issues in fullsend-ai/fullsend:

  • #5295: Skip retro dispatch for bot-authored PRs with zero agent involvement
  • #6297: Extend retro skip logic to merged PRs with zero fullsend agent involvement
  • #4177: Consider skipping or reducing agent effort on automated dependency update PRs
  • #5185: Extend bot PR retro skip to use user.type detection instead of hardcoded bot list

This retro run provides additional evidence for those issues: the repo's fullsend.yaml routing logic already skips Renovate branches for review/code/triage dispatch (open/synchronize/ready_for_review actions) but intentionally preserves retro processing on the closed action. Resolving the upstream issues would eliminate this class of unnecessary retro runs.

No new proposals are warranted — the workflow operated correctly within its current constraints, and all identified improvements are already tracked upstream.

@fullsend-ai-retro

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 4:09 PM UTC · Completed 4:14 PM UTC

Commit: ec561e0 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.41

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant