diff --git a/.github/workflows/audit.yaml b/.github/workflows/audit.yaml index 491748d..1c438f6 100644 --- a/.github/workflows/audit.yaml +++ b/.github/workflows/audit.yaml @@ -129,13 +129,13 @@ jobs: - name: Setup mise id: mise - uses: ./.github/actions/setup-mise + uses: $/.github/actions/setup-mise with: github-token: ${{ github.token }} - name: Resolve toolchain versions id: toolchains - uses: ./.github/actions/mise-tool-versions + uses: $/.github/actions/mise-tool-versions with: executable: ${{ steps.mise.outputs.executable }} @@ -175,13 +175,13 @@ jobs: - name: Setup mise id: mise - uses: ./.github/actions/setup-mise + uses: $/.github/actions/setup-mise with: github-token: ${{ github.token }} - name: Resolve toolchain versions id: toolchains - uses: ./.github/actions/mise-tool-versions + uses: $/.github/actions/mise-tool-versions with: executable: ${{ steps.mise.outputs.executable }} diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 7b3233b..8a96d3a 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -212,13 +212,13 @@ jobs: - name: Setup mise id: mise - uses: ./.github/actions/setup-mise + uses: $/.github/actions/setup-mise with: github-token: ${{ github.token }} - name: Resolve toolchain versions id: toolchains - uses: ./.github/actions/mise-tool-versions + uses: $/.github/actions/mise-tool-versions with: executable: ${{ steps.mise.outputs.executable }} diff --git a/docs/automations/dependency-sweep.md b/docs/automations/dependency-sweep.md index 3ecb99d..426922f 100644 --- a/docs/automations/dependency-sweep.md +++ b/docs/automations/dependency-sweep.md @@ -97,6 +97,14 @@ For automation-owned updates: - run formatting and relevant validation before opening or updating a pull request. +Security scanner upgrades are security maintenance. Do not defer an eligible +scanner release because it reports new findings. Keep the new audits enabled, +remediate actionable findings in the same focused change, and rerun the upgraded +scanner. If a finding appears to be a false positive or calls for a wider +migration, keep the pin upgrade moving and document the finding for human +review. Hold an update only when the scanner itself cannot be installed or run +safely. + ## Pull Requests Use one branch and one pull request per logical dependency domain. Pull requests diff --git a/mise.lock b/mise.lock index 00bc308..3a029c0 100644 --- a/mise.lock +++ b/mise.lock @@ -3,44 +3,44 @@ lockfile_version = 1 [[tools."aqua:zizmorcore/zizmor"]] -version = "1.29.0" +version = "1.30.1" backend = "aqua:zizmorcore/zizmor" -specifiers = ["1.29.0"] +specifiers = ["1.30.1"] [tools."aqua:zizmorcore/zizmor"."platforms.linux-arm64"] -checksum = "sha256:415eaa7c0a06479a701b8e44a3e812c1047decc848ec4bede7bd6bbf49f22d20" -url = "https://github.com/zizmorcore/zizmor/releases/download/v1.29.0/zizmor-aarch64-unknown-linux-gnu.tar.gz" -url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/498263143" +checksum = "sha256:7ff1dce33bdd18fd2a4affe63bdd47efcccca97b2cec1c1863ec26e9e2647540" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-aarch64-unknown-linux-gnu.tar.gz" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067643" provenance = "github-attestations" [tools."aqua:zizmorcore/zizmor"."platforms.linux-arm64-musl"] provenance = "github-attestations" [tools."aqua:zizmorcore/zizmor"."platforms.linux-x64"] -checksum = "sha256:dd96df044a6e8538d5f423790f453bdd03d49e5b2bcc38214acc41a2f1297839" -url = "https://github.com/zizmorcore/zizmor/releases/download/v1.29.0/zizmor-x86_64-unknown-linux-gnu.tar.gz" -url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/498263145" +checksum = "sha256:e65324f4430c2717591937edcec90ccbefaf14c174f8ec9415e03ca875b46e1a" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-x86_64-unknown-linux-gnu.tar.gz" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067642" provenance = "github-attestations" [tools."aqua:zizmorcore/zizmor"."platforms.linux-x64-musl"] provenance = "github-attestations" [tools."aqua:zizmorcore/zizmor"."platforms.macos-arm64"] -checksum = "sha256:720322fade9e83a9c7953944c438f2ba942636b86b96a8f0e6b15ce94c8a6b6f" -url = "https://github.com/zizmorcore/zizmor/releases/download/v1.29.0/zizmor-aarch64-apple-darwin.tar.gz" -url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/498263141" +checksum = "sha256:e28d22b087f9ebb8d99da6e740d348c930f559961c7c3f12badda54f882195a2" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-aarch64-apple-darwin.tar.gz" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067640" provenance = "github-attestations" [tools."aqua:zizmorcore/zizmor"."platforms.macos-x64"] -checksum = "sha256:648b72ab9941a7f2a8d65d7b68a8e76cef789538c8df3a3950384d38423375b0" -url = "https://github.com/zizmorcore/zizmor/releases/download/v1.29.0/zizmor-x86_64-apple-darwin.tar.gz" -url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/498263144" +checksum = "sha256:10e6b18b11ea07e515a16f0f0518c7b07527bc9977c1fd5698181ce7f3554202" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-x86_64-apple-darwin.tar.gz" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067641" provenance = "github-attestations" [tools."aqua:zizmorcore/zizmor"."platforms.windows-x64"] -checksum = "sha256:68a6bc6888f10bf0d53658c75885e7c1b7a0588d4c1fbc3f0ca280ad7324bf06" -url = "https://github.com/zizmorcore/zizmor/releases/download/v1.29.0/zizmor-x86_64-pc-windows-msvc.zip" -url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/498263142" +checksum = "sha256:b183b1e996eddfab9659f1e9b46e059f1ef1cf984a1f14e5da09f7876a4b3a1c" +url = "https://github.com/zizmorcore/zizmor/releases/download/v1.30.1/zizmor-x86_64-pc-windows-msvc.zip" +url_api = "https://api.github.com/repos/zizmorcore/zizmor/releases/assets/552067645" provenance = "github-attestations" [[tools."cargo:bindgen-cli"]] diff --git a/mise.toml b/mise.toml index 2083336..f1d98c2 100644 --- a/mise.toml +++ b/mise.toml @@ -2,7 +2,7 @@ node = "24.21.0" # Rust intentionally tracks the stable channel for this Rust library. rust = { version = "stable", profile = "minimal", components = "clippy,rustfmt" } -"aqua:zizmorcore/zizmor" = "1.29.0" +"aqua:zizmorcore/zizmor" = "1.30.1" "cargo:bindgen-cli" = "0.72.1" "cargo:cargo-deny" = "0.20.2"