Skip to content

Conversation

@alakae
Copy link
Contributor

@alakae alakae commented Jan 8, 2026

There are three changes in this PR:

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@alakae alakae changed the title Pin GitHub Actions Pin GitHub Actions and Improved Zizmor Setup Jan 8, 2026
@alakae
Copy link
Contributor Author

alakae commented Jan 8, 2026

btw. I have used pinact run to pin to the hashes.

Copy link
Collaborator

@mweibel mweibel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

btw. I have used pinact run to pin to the hashes.

I assume in the future, dependabot will take care of this?

About the audit message from GitHub security bot (cooldown missing): I saw that you added it afterwards, right?
Interesting that it didn't notice this and remove the comment.

@alakae
Copy link
Contributor Author

alakae commented Jan 9, 2026

btw. I have used pinact run to pin to the hashes.

I assume in the future, dependabot will take care of this?

Yes, dependabot will create PRs that update both the SHA and the comment with the version number. I just wanted to document this somewhere for future reference.

About the audit message from GitHub security bot (cooldown missing): I saw that you added it afterwards, right? Interesting that it didn't notice this and remove the comment.

Yes, it appeared after I added dependabot config and was marked fixed when I added the cool-down. Where did you see it, here it is marked fixed:

image

@mweibel
Copy link
Collaborator

mweibel commented Jan 9, 2026

Yes, dependabot will create PRs that update both the SHA and the comment with the version number. I just wanted to document this somewhere for future reference.

that's what I expected. Nice 👍

Yes, it appeared after I added dependabot config and was marked fixed when I added the cool-down. Where did you see it, here it is marked fixed:

As mentioned in chat - it seems it only marked it as fixed after my review.

@mweibel mweibel mentioned this pull request Jan 9, 2026
@alakae alakae merged commit 9d9d576 into main Jan 9, 2026
10 checks passed
@alakae alakae deleted the alain/zizmor branch January 9, 2026 08:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants