Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 24, 2025

This PR contains the following updates:

Package Update Change
zizmor minor 1.15.2 -> 1.16.0

Release Notes

zizmorcore/zizmor (zizmor)

v1.16.0

Compare Source

New Features 🌈🔗

Performance Improvements 🚄🔗

  • zizmor's online mode is now significantly (40% to over 95%) faster on common workloads, thanks to a combination of caching improvements and conversion of GitHub API requests into Git remote lookups (#​1257)

    Many thanks to @​Bo98 for implementing these improvements!

Enhancements 🌱🔗

  • When running in --fix mode and all fixes are successfully applied, zizmor now has similar exit code behavior as the --no-exit-codes and --format=sarif flags (#​1242)

    Many thanks to @​cnaples79 for implementing this improvement!

  • The dependabot-cooldown audit now supports auto-fixes for many findings (#​1229)

    Many thanks to @​mostafa for implementing this improvement!

  • The dependabot-execution audit now supports auto-fixes for many findings (#​1229)

    Many thanks to @​mostafa for implementing this improvement!

  • zizmor now has limited, experimental support for handling inputs that contain YAML anchors (#​1266)


Configuration

📅 Schedule: Branch creation - Between 05:00 AM and 09:59 PM, Monday through Friday ( * 5-21 * * MON-FRI ) in timezone Europe/London, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

| datasource      | package           | from    | to      |
| --------------- | ----------------- | ------- | ------- |
| github-releases | zizmorcore/zizmor | v1.15.2 | v1.16.0 |


Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot added the dependencies Pull requests that update a dependency file label Oct 24, 2025
@renovate renovate bot requested a review from martincostello as a code owner October 24, 2025 04:46
Copy link
Contributor

@costellobot costellobot bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approving dependency update.

@costellobot costellobot bot merged commit f3fff00 into main Oct 24, 2025
10 checks passed
@costellobot costellobot bot deleted the renovate/regex/zizmor-1.x branch October 24, 2025 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants