From 1a8a3e69ed0f26e138be3240af19372a7ad25658 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 16 Sep 2026 12:03:35 +0000 Subject: [PATCH 1/3] Bump zizmorcore/zizmor-action from 0.6.2 to 0.6.4 Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.6.2 to 0.6.4. - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](https://github.com/zizmorcore/zizmor-action/compare/3dc1ecc9bcb9e94e9b2c709687979e1298497054...cc914d7f3750a2d13d75c7f184a1060aa0e9d482) --- updated-dependencies: - dependency-name: zizmorcore/zizmor-action dependency-version: 0.6.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/zizmor.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 0fb3f3580c..7430789b7c 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -46,6 +46,6 @@ jobs: persist-credentials: false - name: Run zizmor - uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 + uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4 with: advanced-security: ${{ github.repository_owner == 'apache' && github.event_name == 'push' }} From 46e1a1b9388bcf8160fff4b9a3b06e380dca1472 Mon Sep 17 00:00:00 2001 From: "Doroszlai, Attila" Date: Wed, 16 Sep 2026 14:10:52 +0200 Subject: [PATCH 2/3] use '$/...' instead of './...' --- .github/workflows/ci.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 06e749a218..cb1dd3ac02 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -36,13 +36,13 @@ permissions: jobs: static: - uses: ./.github/workflows/static.yml + uses: $/.github/workflows/static.yml docusaurus: needs: static - uses: ./.github/workflows/docusaurus.yml + uses: $/.github/workflows/docusaurus.yml publish: needs: docusaurus if: ${{ github.event_name == 'push' && github.ref_name == 'master' }} - uses: ./.github/workflows/publish.yml + uses: $/.github/workflows/publish.yml permissions: contents: write From 457c887a85f27b12ae218865d8eb074e47ae2478 Mon Sep 17 00:00:00 2001 From: "Doroszlai, Attila" Date: Wed, 16 Sep 2026 14:11:31 +0200 Subject: [PATCH 3/3] bump allowlist-check to 1.0.3 --- .github/workflows/asf-allowlist-check.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/asf-allowlist-check.yaml b/.github/workflows/asf-allowlist-check.yaml index 61998ee558..ddfa51f853 100644 --- a/.github/workflows/asf-allowlist-check.yaml +++ b/.github/workflows/asf-allowlist-check.yaml @@ -46,6 +46,6 @@ jobs: persist-credentials: false - name: Check actions # yamllint disable-line rule:line-length - uses: apache/infrastructure-actions/allowlist-check@61dcea11f19e2bbe1263f14d72235e8da17d3ad0 # allowlist-check/v1.0.0 + uses: apache/infrastructure-actions/allowlist-check@60e90f7a665a68248f145b8b2c97ed712132495b # allowlist-check/v1.0.3 with: scan-glob: .github/workflows/*.y*ml