Skip to content

feat: add support for ratchet ref pin comments - #2319

Merged
woodruffw merged 2 commits into
zizmorcore:mainfrom
njgudman:njgudman/support-ratchet
Aug 23, 2026
Merged

woodruffw merged 2 commits into
zizmorcore:mainfrom
njgudman:njgudman/support-ratchet

Conversation

@njgudman

Copy link
Copy Markdown
Contributor

adds a regex that accepts ratchet git ref comments used to pin and unpin github actions

Generated with copilot

Refs: #2316

Pre-submission checks

Please check these boxes:

  • Mandatory: This PR corresponds to an issue (if not, please create
    one first).

  • Having read the AI policy, I hereby disclose the use of an LLM or other
    AI coding assistant in the creation of this PR. PRs will not be rejected
    for using AI tools, but will be rejected for undisclosed use or
    use that violates the policy.

If a checkbox is not applicable, you can leave it unchecked.

Summary

Add a regular expression to process github actions references pinned to git shas with ratchet so that the ref-version-mismatch check passes.

Test Plan

Includes unit test that use ratchet's pin comment format

@woodruffw woodruffw added the enhancement New feature or request label Aug 23, 2026
@woodruffw woodruffw added this to the 1.30.0 milestone Aug 23, 2026
adds a regex that accepts ratchet git ref comments used to
pin and unpin github actions

Generated with copilot

Refs: zizmorcore#2316

Signed-off-by: Nick Gudman <njgudman@gmail.com>
@woodruffw
woodruffw force-pushed the njgudman/support-ratchet branch from 18b17c3 to 4b22471 Compare August 23, 2026 19:19

@woodruffw woodruffw left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @njgudman!

@woodruffw
woodruffw merged commit dda823e into zizmorcore:main Aug 23, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants