Skip to content

Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 in the github-actions group across 1 directory#1271

Merged
duncanmcclean merged 3 commits into
8.xfrom
dependabot/github_actions/github-actions-44be538ff8
May 25, 2026
Merged

Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 in the github-actions group across 1 directory#1271
duncanmcclean merged 3 commits into
8.xfrom
dependabot/github_actions/github-actions-44be538ff8

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 25, 2026

Bumps the github-actions group with 1 update in the / directory: zizmorcore/zizmor-action.

Updates zizmorcore/zizmor-action from 0.5.3 to 0.5.6

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.5.6

  • 1.25.2 is now available via the action
  • 1.25.2 is now the default version of zizmor used by the action

v0.5.5

This is a no-op release.

v0.5.4

  • 1.25.0 is now available via the action
  • 1.25.0 is now the default version of zizmor used by the action
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 25, 2026
@duncanmcclean
Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps the github-actions group with 1 update in the / directory: [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).


Updates `zizmorcore/zizmor-action` from 0.5.3 to 0.5.6
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@b1d7e1f...5f14fd0)

---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.5.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 in the github-actions group Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 in the github-actions group across 1 directory May 25, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/github-actions-44be538ff8 branch from 324a1b1 to 0227edd Compare May 25, 2026 17:03
duncanmcclean and others added 2 commits May 25, 2026 18:42
Set persist-credentials: false on checkout and use explicit token URL for git push.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Avoids zizmor code injection warnings by passing secrets and context
through environment variables instead of inline template expansion.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@duncanmcclean duncanmcclean merged commit e64a2ca into 8.x May 25, 2026
1 of 14 checks passed
@duncanmcclean duncanmcclean deleted the dependabot/github_actions/github-actions-44be538ff8 branch May 25, 2026 18:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant