From f0b5ef5d13f0b1c9a2692224e808068a96d32b04 Mon Sep 17 00:00:00 2001 From: "pre-commit-ci[bot]" <66853113+pre-commit-ci[bot]@users.noreply.github.com> Date: Mon, 12 May 2025 17:25:58 +0000 Subject: [PATCH 1/5] [pre-commit.ci] pre-commit autoupdate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit updates: - [github.com/woodruffw/zizmor-pre-commit: v1.5.2 → v1.7.0](https://github.com/woodruffw/zizmor-pre-commit/compare/v1.5.2...v1.7.0) --- .pre-commit-config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 640448e..1579aeb 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -15,7 +15,7 @@ repos: args: [--fix, lf] - id: trailing-whitespace - repo: https://github.com/woodruffw/zizmor-pre-commit - rev: v1.5.2 + rev: v1.7.0 hooks: - id: zizmor From 61f1dc10052cbe032541529be653c92a94d87dfc Mon Sep 17 00:00:00 2001 From: Oleg Smirnov Date: Sat, 17 May 2025 16:53:47 +0200 Subject: [PATCH 2/5] add idea files to gitignore --- .gitignore | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.gitignore b/.gitignore index a2a3c20..db9408d 100644 --- a/.gitignore +++ b/.gitignore @@ -8,3 +8,7 @@ build gradle/wrapper gradlew gradlew.bat + +# IDEA +.idea +out/ \ No newline at end of file From 7d039445f6f325801a4773aac3f1bb19c504a138 Mon Sep 17 00:00:00 2001 From: Oleg Smirnov Date: Sat, 17 May 2025 16:57:48 +0200 Subject: [PATCH 3/5] correct zizmor url due to migration in 1.8.0 --- .pre-commit-config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 1579aeb..6a1cde7 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -14,7 +14,7 @@ repos: - id: mixed-line-ending args: [--fix, lf] - id: trailing-whitespace - - repo: https://github.com/woodruffw/zizmor-pre-commit + - repo: https://github.com/zizmorcore/zizmor-pre-commit rev: v1.7.0 hooks: - id: zizmor From 4914dd1896a7d3cbc1a30d273a0cf4496a64e049 Mon Sep 17 00:00:00 2001 From: Oleg Smirnov Date: Sat, 17 May 2025 17:02:58 +0200 Subject: [PATCH 4/5] add zizmor configuration to allow ref-pin actions --- zizmor.yml | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 zizmor.yml diff --git a/zizmor.yml b/zizmor.yml new file mode 100644 index 0000000..e37c0a6 --- /dev/null +++ b/zizmor.yml @@ -0,0 +1,6 @@ +rules: + unpinned-uses: + config: + policies: + actions/*: ref-pin + "*": ref-pin \ No newline at end of file From 777480c4edad61845c29b82a5ee8387aa2ca303a Mon Sep 17 00:00:00 2001 From: "pre-commit-ci[bot]" <66853113+pre-commit-ci[bot]@users.noreply.github.com> Date: Sat, 17 May 2025 15:03:20 +0000 Subject: [PATCH 5/5] [pre-commit.ci] auto fixes from pre-commit.com hooks for more information, see https://pre-commit.ci --- .gitignore | 2 +- zizmor.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index db9408d..1ca2998 100644 --- a/.gitignore +++ b/.gitignore @@ -11,4 +11,4 @@ gradlew.bat # IDEA .idea -out/ \ No newline at end of file +out/ diff --git a/zizmor.yml b/zizmor.yml index e37c0a6..efced06 100644 --- a/zizmor.yml +++ b/zizmor.yml @@ -3,4 +3,4 @@ rules: config: policies: actions/*: ref-pin - "*": ref-pin \ No newline at end of file + "*": ref-pin