Bare pin comments: let Dependabot maintain action version comments - #576
Conversation
…n comments Dependabot rewrites bare version comments natively but cannot touch compound ones carrying a trailing zizmor ignore. One line per pin plus a standalone ignore below it (same restructure as basecamp-sdk#458) makes Dependabot the first line of defense with no push automation needed on its PRs. Also normalizes zizmor-action to v0.6.0 so the audit runs a zizmor that associates standalone ignore comments (the 1.23-era resolution of older action versions does not).
Sensitive Change Detection (shadow mode)This PR modifies control-plane files:
|
There was a problem hiding this comment.
Pull request overview
This PR adjusts GitHub Actions workflow annotations so Dependabot can maintain the bare pinned-action version comments automatically, while keeping zizmor ignores effective (by moving them onto their own adjacent comment line). It also bumps the zizmorcore/zizmor-action version to ensure standalone ignore comments are recognized.
Changes:
- Bump
zizmorcore/zizmor-actionpin from v0.5.7 to v0.6.0 in the CI workflow. - Refactor
release.ymlto move trailing# zizmor: ignore[...]from inlineuses:comments onto their own line directly below the pin (reasons preserved).
Tip
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| .github/workflows/test.yml | Updates the pinned zizmorcore/zizmor-action SHA/comment to v0.6.0. |
| .github/workflows/release.yml | Splits inline zizmor ignore annotations onto their own adjacent line so Dependabot can manage bare # vX.Y.Z comments. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Dependabot rewrites bare
# vX.Y.Zcomments on pinneduses:lines natively but cannot touch compound ones carrying a trailing# zizmor: ignore[...]. Moving each ignore to its own line directly below the pin (reason text kept, association verified under zizmor 1.28) makes Dependabot itself the comment maintainer — no push automation required on its PRs. Same restructure basecamp-sdk shipped in basecamp-sdk#458. Part of the post-merge redesign of the comment-sync program (see basecamp/.github#10 for why in-PR pushing is unsafe: a deploy-key push flips the run actor off dependabot[bot] and lifts the Dependabot sandbox for the unreviewed bumped actions).Summary by cubic
Move
zizmorignores to their own line under each pinneduses:so Dependabot can update bare# vX.Y.Zcomments automatically. Upgradezizmorcore/zizmor-actionto v0.6.0 to ensure standalone ignore comments are recognized.Refactors
# zizmor: ignore[...]offuses:pins inrelease.yml; reasons preserved.Dependencies
zizmorcore/zizmor-actionfrom v0.5.7 to v0.6.0 intest.ymlto support standalone ignore association.Written for commit eda3bc4. Summary will update on new commits.