chore(deps): bump zizmor-action to 0.6.3 - #3161
Merged
Merged
Conversation
kevinjqliu
pushed a commit
that referenced
this pull request
Sep 10, 2026
* fix(ci): keep .github/actions in the source archive `.github export-ignore` (#3189) hides `.github/actions` from repository archives. GitHub resolves the `uses: $/...` self-repository references introduced in #3161 by fetching such an archive, so every workflow that uses a local composite action now fails at action resolution: Can't find 'action.yml', 'action.yaml' or 'Dockerfile' for action 'apache/iceberg-rust/.github/actions/setup-builder@<sha>' This breaks CI on main and on all open pull requests. List the .github entries individually instead, so the repo-only files #3189 targeted stay out of the release tarball while `.github/actions` remains resolvable. A `-export-ignore` negation on the subdirectory does not work: git does not descend into an export-ignored directory. * comment
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Which issue does this PR close?
What changes are included in this PR?
zizmorcore/zizmor-actionfrom v0.6.2 to v0.6.3../...to GitHub self-repository$/...references, resolving the new zizmor 1.30 audit.$/...references only in the ASF allowlist job disposable checkout because the current checker recognizes./..., but not$/..., as local. External action references remain unchanged and fully checked.No zizmor audit is ignored or disabled.
Are these changes tested?
uvx zizmor@1.30.0 --strict-collection --persona=regular --collect=default --color=never .(no findings; 44 existing suppressions)git diff --check upstream/main...HEADAI Disclosure
AI was used to inspect the #3158 CI failure, identify the ASF allowlist checker compatibility issue, apply the workflow updates, and draft this PR description. I reviewed the changes and validated them with the exact zizmor and ASF checker versions used by CI.