Skip to content

[CHORE](gha)(deps): Bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3#21

Merged
John McCall (lowlydba) merged 2 commits intomainfrom
dependabot/github_actions/zizmorcore/zizmor-action-0.5.3
Apr 22, 2026
Merged

[CHORE](gha)(deps): Bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3#21
John McCall (lowlydba) merged 2 commits intomainfrom
dependabot/github_actions/zizmorcore/zizmor-action-0.5.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

Bumps zizmorcore/zizmor-action from 0.5.2 to 0.5.3.

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.5.3

What's Changed

  • 1.24.0 and 1.24.1 are now available via the action
  • 1.24.1 is now the default version of zizmor used by the action

Full Changelog: zizmorcore/zizmor-action@v0.5.2...v0.5.3

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.2 to 0.5.3.
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@71321a2...b1d7e1f)

---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the bot Automated bot pull requests label Apr 21, 2026
@dependabot dependabot Bot requested review from a team and John McCall (lowlydba) as code owners April 21, 2026 10:18
@dependabot dependabot Bot added the bot Automated bot pull requests label Apr 21, 2026
@dependabot dependabot Bot temporarily deployed to check-linked-issue-app April 21, 2026 10:19 Inactive
@overture-projection
Copy link
Copy Markdown

overture-projection Bot commented Apr 22, 2026

Overture PRojection Review

This PR updates the zizmorcore/zizmor-action GitHub Action from v0.5.2 to v0.5.3 in the security checks workflow and changes the runner label from ubuntu-slim to ubuntu-latest in the projection workflow.

✅ Checks Passed

  • Dependency update is to a patch release with no breaking changes per upstream notes.
  • The runner label change to ubuntu-latest is valid per org conventions.

🚩 Flags

  • PR process: No linked issue (Linked issue: ❌ none). Overture process requires all work to have an associated GitHub issue for visibility and traceability. Please create and link an issue for this change.

❓ Open Questions

  • None.

No bugs, logic errors, or security issues identified in the visible changes. The dependency update is in line with upstream recommendations, and the runner label is compliant with org guidance. The only required action is to link an issue per Overture process.

Signed-off-by: John McCall <john@overturemaps.org>
@lowlydba John McCall (lowlydba) force-pushed the dependabot/github_actions/zizmorcore/zizmor-action-0.5.3 branch from daaba31 to afc961d Compare April 22, 2026 20:36
@lowlydba John McCall (lowlydba) deployed to check-linked-issue-app April 22, 2026 20:36 — with GitHub Actions Active
@lowlydba John McCall (lowlydba) merged commit 3d67f2a into main Apr 22, 2026
8 checks passed
@lowlydba John McCall (lowlydba) deleted the dependabot/github_actions/zizmorcore/zizmor-action-0.5.3 branch April 22, 2026 20:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot Automated bot pull requests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant