Commit graph

25 commits

Author SHA1 Message Date
William Woodruff
e134107e65
fix: allow expressions in shell: clauses (#1336)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Test (push) Waiting to run
CI / Test site build (push) Waiting to run
CI / All tests pass (push) Blocked by required conditions
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (manylinux) (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build macOS wheels (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (musllinux) (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build Windows wheels (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build source distribution (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Release (push) Blocked by required conditions
Deploy zizmor documentation site 🌐 / Deploy zizmor documentation to GitHub Pages 🌐 (push) Waiting to run
GitHub Actions Security Analysis with zizmor 🌈 / Run zizmor 🌈 (push) Waiting to run
2025-11-12 10:54:29 -05:00
William Woodruff
70d35617c2
fix: dependabot: allow 'day' field for non-weekly intervals (#1308) 2025-11-02 00:03:58 +00:00
William Woodruff
965d9ffccc
feat(models): support Dependabot multi-ecosystem groups (#1260)
Some checks are pending
Benchmark baseline / Continuous Benchmarking with Bencher (push) Waiting to run
CI / Lint (push) Waiting to run
CI / Test (push) Waiting to run
CI / Test site build (push) Waiting to run
CI / All tests pass (push) Blocked by required conditions
zizmor wheel builds for PyPI 🐍 / Build source distribution (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Release (push) Blocked by required conditions
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (manylinux) (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (musllinux) (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build Windows wheels (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build macOS wheels (push) Waiting to run
Deploy zizmor documentation site 🌐 / Deploy zizmor documentation to GitHub Pages 🌐 (push) Waiting to run
GitHub Actions Security Analysis with zizmor 🌈 / Run zizmor 🌈 (push) Waiting to run
2025-10-16 23:17:01 -04:00
Joe Wallwork
5b5ad5d924
New audit: concurrency-limits (#1227)
Co-authored-by: William Woodruff <william@yossarian.net>
2025-10-16 20:24:19 -04:00
William Woodruff
41b39833af
bump github-actions-models to 0.36.0 (#1248) 2025-10-14 10:35:41 -04:00
Kingsword
2189780f91
feat: Add validation for extended Dependabot schedule intervals (#1247)
Co-authored-by: William Woodruff <william@yossarian.net>
2025-10-14 10:31:04 -04:00
William Woodruff
e9e4eb9ec4
models: add devcontainers as a known ecosystem (#1240) 2025-10-13 23:08:56 -04:00
William Woodruff
6e1a300ebf
chore: bump github-actions-models to 0.33.0 (#1233) 2025-10-13 18:17:11 -04:00
William Woodruff
76c1b19008
feat: new audit: dependabot-cooldown (#1223)
Some checks failed
CI / Test site build (push) Has been cancelled
zizmor wheel builds for PyPI 🐍 / Build source distribution (push) Has been cancelled
CI / Test (push) Has been cancelled
Benchmark baseline / Continuous Benchmarking with Bencher (push) Has been cancelled
CI / Lint (push) Has been cancelled
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (manylinux) (push) Has been cancelled
zizmor wheel builds for PyPI 🐍 / Build macOS wheels (push) Has been cancelled
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (musllinux) (push) Has been cancelled
zizmor wheel builds for PyPI 🐍 / Build Windows wheels (push) Has been cancelled
Deploy zizmor documentation site 🌐 / Deploy zizmor documentation to GitHub Pages 🌐 (push) Has been cancelled
GitHub Actions Security Analysis with zizmor 🌈 / Run zizmor 🌈 (push) Has been cancelled
CI / All tests pass (push) Has been cancelled
zizmor wheel builds for PyPI 🐍 / Release (push) Has been cancelled
2025-10-07 21:02:24 -04:00
William Woodruff
fbd86b5955
feat: begin scaffolding for Dependabot support (#1215)
Some checks are pending
Benchmark baseline / Continuous Benchmarking with Bencher (push) Waiting to run
CI / Lint (push) Waiting to run
CI / Test (push) Waiting to run
CI / Test site build (push) Waiting to run
CI / All tests pass (push) Blocked by required conditions
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (manylinux) (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (musllinux) (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Release (push) Blocked by required conditions
zizmor wheel builds for PyPI 🐍 / Build Windows wheels (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build macOS wheels (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build source distribution (push) Waiting to run
Deploy zizmor documentation site 🌐 / Deploy zizmor documentation to GitHub Pages 🌐 (push) Waiting to run
GitHub Actions Security Analysis with zizmor 🌈 / Run zizmor 🌈 (push) Waiting to run
2025-10-06 17:46:17 -04:00
William Woodruff
94966bbab8
github-actions-models: remove token from vendored testcase (#1211)
Some checks are pending
Benchmark baseline / Continuous Benchmarking with Bencher (push) Waiting to run
CI / Lint (push) Waiting to run
CI / Test (push) Waiting to run
CI / Test site build (push) Waiting to run
CI / All tests pass (push) Blocked by required conditions
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (manylinux) (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build Linux wheels (musllinux) (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build Windows wheels (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build macOS wheels (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Build source distribution (push) Waiting to run
zizmor wheel builds for PyPI 🐍 / Release (push) Blocked by required conditions
Deploy zizmor documentation site 🌐 / Deploy zizmor documentation to GitHub Pages 🌐 (push) Waiting to run
GitHub Actions Security Analysis with zizmor 🌈 / Run zizmor 🌈 (push) Waiting to run
2025-10-03 16:00:08 -04:00
William Woodruff
dbc12d4a21
chore: prep release v1.12.1 (#1083) 2025-08-15 00:27:09 -04:00
Mostafa Moradian
558bec2669
Add Fix for known-vulnerable-actions audit rule (#1019)
Co-authored-by: William Woodruff <william@yossarian.net>
2025-07-20 21:08:14 -04:00
William Woodruff
353b4017cb
refactor: add subfeature crate (#1030) 2025-07-17 02:08:29 +00:00
William Woodruff
18d5c30c1c
chore(deps): bump all support crate versions (#970) 2025-06-24 18:33:18 -06:00
Rui Chen
816a92d45e
chore(tests): update default branch for homebrew actions (#962)
Signed-off-by: Rui Chen <rui@chenrui.dev>
2025-06-22 17:07:18 -04:00
William Woodruff
f03869f52b
feat: location subspans/subfeatures (#949) 2025-06-19 16:41:39 -04:00
William Woodruff
64f9be57c9
feat: better error messages for invalid inputs (#956) 2025-06-19 12:16:03 -04:00
William Woodruff
0c13e094ee
feat: model input capabilities in workflows and actions (#919) 2025-06-08 14:50:52 -04:00
William Woodruff
cadc304d2a
refactor: add RewriteFragment for format-preserving YAML string edits (#888)
Co-authored-by: Mostafa Moradian <mostafa@grafana.com>
2025-06-04 22:06:45 +00:00
William Woodruff
a4a657f9be
fix: remove spurious panic in env handling (#887) 2025-06-02 14:34:06 -04:00
William Woodruff
37d9d71953
crates: use [lints] table to inherit from workspace (#880) 2025-05-30 18:45:01 -04:00
Langston Barrett
502e82ad71
chore(ci): Small improvements around linting (#879) 2025-05-30 22:03:19 +00:00
William Woodruff
cb91ab95c8
fix: handle booleans for insecure-commands correctly (#840) 2025-05-21 23:24:57 +00:00
William Woodruff
c1c655b452
refactor: bring in github-actions-models (#830) 2025-05-20 14:51:43 -04:00