chore(deps): update pre-commit hook zizmorcore/zizmor-pre-commit to v1.30.0 - #85
Conversation
…1.30.0 Signed-off-by: hermes-renovate[bot] <286339580+hermes-renovate[bot]@users.noreply.github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
PR #85 is a straightforward Renovate bot dependency bump — updating The only agent involvement was this retro dispatch, triggered on merge. Since there was zero prior agent activity to retrospect on, this retro run produced no actionable findings — it is pure overhead. This scenario — retro dispatching on bot-authored PRs with no agent involvement — is already well-covered by existing upstream issues in fullsend-ai/fullsend:
This retro run provides additional evidence for those issues: the repo's No new proposals are warranted — the workflow operated correctly within its current constraints, and all identified improvements are already tracked upstream. |
|
🤖 Finished Retro · ✅ Success · Started 4:09 PM UTC · Completed 4:14 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.41 |
This PR contains the following updates:
v1.29.0→v1.30.0v1.30.1Note: The
pre-commitmanager in Renovate is not supported by thepre-commitmaintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.Release Notes
zizmorcore/zizmor-pre-commit (zizmorcore/zizmor-pre-commit)
v1.30.0Compare Source
Sponsorship is appreciated!
New Features 🌈🔗
New audit: self-repository detects usages of the old "workspace-relative" form for local reusable workflows and actions and recommends the new "self-repository" form instead (#2271)
Enhancements 🌱🔗
The impostor-commit audit now supports pre-commit config inputs (#2256)
The forbidden-uses audit now supports pre-commit config inputs (#2263)
The adhoc-packages audit now detects more ad-hoc package management patterns, including bundle add and yarn add
Many thanks to @connorshea for proposing and implementing this enhancement!
The archived-uses audit now supports pre-commit config inputs (#2272)
The ref-confusion audit now supports pre-commit config inputs (#2274)
The cache-poisoning audit now produces more detailed and more precise diagnostics (#2330)
The cache-poisoning audit now handles and exposes auto-fixes in a more general manner (#2332)
zizmor now recognizes sethvargo/ratchet version comments when evaluating ref pinning (#2319)
Many thanks to @njgudman for proposing and implementing this enhancement!
The unpinned-tools audit now produces more detailed and more precise diagnostics (#2339)
The unpinned-tools audit now detects usages of extractions/setup-just (#2339)
The unpinned-tools audit now detects usages of extractions/setup-crate (#2340)
The archived-uses audit now detects several more archived repositories (#2340)
The ref-version-mismatch audit now supports uses: that reference reusable workflows (#2344)
The stale-action-refs audit now supports uses: that reference reusable workflows (#2345)
Bug Fixes 🐛🔗
Fixed a bug where zizmor would reject a .pre-commit-config.yml input containing a prek-specific builtin section (#2259)
Fixed a bug where the unpinned-uses audit would fail to honor ignore comments within the same step scope (#2289)
Fixed a bug where zizmor would reject a dependabot.yml containing a goproxy-server registry definition (#2300)
Fixed a bug where zizmor would reject pre-commit configurations containing prek-specific glob patterns in files or exclude (#2308)
Fixed a handful of unsound patch bugs when performing YAML add and/or replace operations (#2295)
Many thanks to @dmbuil for proposing and implementing this improvement!
Fixed a bug where the cache-poisoning audit would incorrectly flag newer astral-sh/setup-uv versions that disable caching behavior automatically (#2330)
Fixed a bug where the ref-version-mismatch audit would produce a misleading diagnostic when an action has overlapping branch and tag names (#2337)
Fixed a bug where the artipacked audit would incorrectly flag the with: clauses of unrelated actions (#2339)
Fixed a class of bugs where zizmor would incorrectly match an action's commit to a sibling action's tag (#2247)
Many thanks to @potiuk for proposing and implementing this improvement!
Fixed a bug where zizmor would crash on deeply nested GitHub Actions expressions (#2349)
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.