Skip to content

Extend RepositoryUsesPattern to RepoRef - #2263

Merged
woodruffw merged 8 commits into
mainfrom
ww/pattern
Aug 2, 2026
Merged

woodruffw merged 8 commits into
mainfrom
ww/pattern

Conversation

@woodruffw

Copy link
Copy Markdown
Member

...so that it works with slugs as well. This will unblock some of the parity audits in #2256.

@woodruffw woodruffw self-assigned this Aug 2, 2026
@woodruffw woodruffw mentioned this pull request Aug 2, 2026
4 of 13 tasks
@woodruffw
woodruffw marked this pull request as ready for review August 2, 2026 20:50
@woodruffw
woodruffw merged commit 9829bb6 into main Aug 2, 2026
14 checks passed
@woodruffw
woodruffw deleted the ww/pattern branch August 2, 2026 21:07
@woodruffw woodruffw added this to the 1.30.0 milestone Aug 7, 2026
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `zizmor`

Command: `mise upgrade --bump --local zizmor`

<details>
<summary>Version changelog (zizmor)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `zizmor` | `1.29.0` → `1.30.0` | `1.29.0` → `1.30.0` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>zizmor: `1.29.0` → `1.30.0` (zizmorcore/zizmor)</summary>

### v1.30.0

[Sponsorship is appreciated!](https://github.com/sponsors/woodruffw/)

## New Features 🌈[🔗](https://docs.zizmor.sh/release-notes/#new-features)

- New audit: [self-repository](https://docs.zizmor.sh/audits/#self-repository) detects usages of the old "workspace-relative" form for local reusable workflows and actions and recommends the new "self-repository" form instead ([#2271](zizmorcore/zizmor#2271))
Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The [impostor-commit](https://docs.zizmor.sh/audits/#impostor-commit) audit now supports pre-commit config inputs ([#2256](zizmorcore/zizmor#2256))

- The [forbidden-uses](https://docs.zizmor.sh/audits/#forbidden-uses) audit now supports pre-commit config inputs ([#2263](zizmorcore/zizmor#2263))

- The [adhoc-packages](https://docs.zizmor.sh/audits/#adhoc-packages) audit now detects more ad-hoc package management patterns, including bundle add and yarn add

    Many thanks to [@​connorshea](https://github.com/connorshea) for proposing and implementing this enhancement!

- The [archived-uses](https://docs.zizmor.sh/audits/#archived-uses) audit now supports pre-commit config inputs ([#2272](zizmorcore/zizmor#2272))

- The [ref-confusion](https://docs.zizmor.sh/audits/#ref-confusion) audit now supports pre-commit config inputs ([#2274](zizmorcore/zizmor#2274))

- The [cache-poisoning](https://docs.zizmor.sh/audits/#cache-poisoning) audit now produces more detailed and more precise diagnostics ([#2330](zizmorcore/zizmor#2330))

- The [cache-poisoning](https://docs.zizmor.sh/audits/#cache-poisoning) audit now handles and exposes auto-fixes in a more general manner ([#2332](zizmorcore/zizmor#2332))

- zizmor now recognizes [sethvargo/ratchet](https://github.com/sethvargo/ratchet) versi… (truncated)

### v1.30.0-rc1

_No release notes provided._

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `zizmor`

Command: `mise upgrade --bump --local zizmor`

<details>
<summary>Version changelog (zizmor)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `zizmor` | `1.29.0` → `1.30.0` | `1.29.0` → `1.30.0` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>zizmor: `1.29.0` → `1.30.0` (zizmorcore/zizmor)</summary>

### v1.30.0

[Sponsorship is appreciated!](https://github.com/sponsors/woodruffw/)

## New Features 🌈[🔗](https://docs.zizmor.sh/release-notes/#new-features)

- New audit: [self-repository](https://docs.zizmor.sh/audits/#self-repository) detects usages of the old "workspace-relative" form for local reusable workflows and actions and recommends the new "self-repository" form instead ([#2271](zizmorcore/zizmor#2271))
Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The [impostor-commit](https://docs.zizmor.sh/audits/#impostor-commit) audit now supports pre-commit config inputs ([#2256](zizmorcore/zizmor#2256))

- The [forbidden-uses](https://docs.zizmor.sh/audits/#forbidden-uses) audit now supports pre-commit config inputs ([#2263](zizmorcore/zizmor#2263))

- The [adhoc-packages](https://docs.zizmor.sh/audits/#adhoc-packages) audit now detects more ad-hoc package management patterns, including bundle add and yarn add

    Many thanks to [@​connorshea](https://github.com/connorshea) for proposing and implementing this enhancement!

- The [archived-uses](https://docs.zizmor.sh/audits/#archived-uses) audit now supports pre-commit config inputs ([#2272](zizmorcore/zizmor#2272))

- The [ref-confusion](https://docs.zizmor.sh/audits/#ref-confusion) audit now supports pre-commit config inputs ([#2274](zizmorcore/zizmor#2274))

- The [cache-poisoning](https://docs.zizmor.sh/audits/#cache-poisoning) audit now produces more detailed and more precise diagnostics ([#2330](zizmorcore/zizmor#2330))

- The [cache-poisoning](https://docs.zizmor.sh/audits/#cache-poisoning) audit now handles and exposes auto-fixes in a more general manner ([#2332](zizmorcore/zizmor#2332))

- zizmor now recognizes [sethvargo/ratchet](https://github.com/sethvargo/ratchet) versi… (truncated)

### v1.30.0-rc1

_No release notes provided._

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant