Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 26, 2025

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Package Update Change
zizmor minor 1.13.0 -> 1.14.0

Release Notes

zizmorcore/zizmor (zizmor)

v1.14.0

Compare Source

New Features 🌈🔗

Enhancements 🌱🔗

  • zizmor no longer uses the "Unknown" severity or confidence levels for any findings. All findings previously categorized at these levels are now given a more meaningful level (#​1164)

  • The use-trusted-publishing audit now detects various Trusted Publishing patterns for the npm ecosystem (#​1161)

    Many thanks to @​KristianGrafana for implementing this improvement!

  • The unsound-condition audit now supports auto-fixes for many findings (#​1089)

    Many thanks to @​mostafa for implementing this improvement!

  • zizmor's error handling has been restructured, improving the quality of error messages and their associated suggestions (#​1169)

Bug Fixes 🐛🔗

  • Fixed a bug where the cache-poisoning audit would fail to detect some cache usage variants in newer versions of actions/setup-node (#​1152)

  • Fixed a bug where the obfuscation audit would incorrectly flag some subexpressions as constant-reducible when they were not (#​1170)

Deprecations ⚠️🔗

  • The unknown values for --min-severity and --min-confidence are now deprecated. These values were already no-ops (and have been since introduction), and will be removed in a future release (#​1164)

    Until removal, using these values will emit a warning.


Configuration

📅 Schedule: Branch creation - Between 05:00 AM and 09:59 PM, Monday through Friday ( * 5-21 * * MON-FRI ) in timezone Europe/London, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

| datasource      | package           | from    | to      |
| --------------- | ----------------- | ------- | ------- |
| github-releases | zizmorcore/zizmor | v1.13.0 | v1.14.0 |


Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot added the dependencies Pull requests that update a dependency file label Sep 26, 2025
@renovate renovate bot requested a review from martincostello as a code owner September 26, 2025 16:46
Copy link
Contributor

@costellobot costellobot bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approving dependency update.

@costellobot costellobot bot enabled auto-merge (squash) September 26, 2025 18:31
@costellobot costellobot bot merged commit 5f9ac38 into main Sep 26, 2025
10 of 11 checks passed
@costellobot costellobot bot deleted the renovate/regex/zizmor-1.x branch September 26, 2025 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant