Skip to content

chore(ci): bump NDDev-OpenNetwork/ci-workflows/.github/workflows/zizmor-sarif.yml from 1ab6708b62ec7bd17f2d8a519c6fcc39edb22243 to 9231ee7421354867b0fe0e019c4e20dcce5d05e7 - #46

Merged
rldyourmnd merged 1 commit into
mainfrom
dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/zizmor-sarif.yml-9231ee7421354867b0fe0e019c4e20dcce5d05e7
Sep 10, 2026
Merged

chore(ci): bump NDDev-OpenNetwork/ci-workflows/.github/workflows/zizmor-sarif.yml from 1ab6708b62ec7bd17f2d8a519c6fcc39edb22243 to 9231ee7421354867b0fe0e019c4e20dcce5d05e7#46
rldyourmnd merged 1 commit into
mainfrom
dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/zizmor-sarif.yml-9231ee7421354867b0fe0e019c4e20dcce5d05e7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Contributor

Bumps NDDev-OpenNetwork/ci-workflows/.github/workflows/zizmor-sarif.yml from 1ab6708b62ec7bd17f2d8a519c6fcc39edb22243 to 9231ee7421354867b0fe0e019c4e20dcce5d05e7.

Changelog

Sourced from NDDev-OpenNetwork/ci-workflows/.github/workflows/zizmor-sarif.yml's changelog.

Changelog

This file is a release ledger: every heading below is a real release, and scripts/check_release_ledger.py enforces that in both directions.

The project follows Semantic Versioning.

[Unreleased]

  • Add optional check_name to the private-free security bundle so callers can retain an existing required check identity when migrating away from SARIF publication, with all four scanners and evidence artifacts preserved.

  • Synchronize pins by catalog action family, preserving independent subpath actions and reusable workflows in the same repository. Apply the reviewed dependency updates from #92 with matching catalog and transitive-image records; historical evidence digests are no longer rewritten by an unrelated action update.

  • Stop treating the publisher as an Enterprise Cloud buyer of Code Security, Secret Protection and Code Quality. Paid programmes stay explicitly selectable; public CodeQL, SARIF, Scorecard and attestations stay. Private repositories without those purchases use the private-free programme. A live GitHub plan belongs to one organization and is not copied between accounts. Consumer adoption resolves the programme from the immutable release being pinned, not from main. Private attestations stay an Enterprise Cloud plan gate, independent of the three add-ons.

  • Dependabot catalog convergence commits only catalog and generated docs, so the default GITHUB_TOKEN can push without workflows permission. Catalog-only follows the unique workflow pin per action and fails closed when identities are mixed, so the catalog cannot describe a pin the tree does not share. Ordinary merge in this repository does not require a general CI status check; ci-gate stays truthful advisory evidence. Authored skill metadata: mappings stay mappings.

  • Re-verify four vendor allowance records with staggered review dates, correct Ubicloud's monthly credit and Harness's conditional CI credit semantics, and align the disclosed Checkov image tag with the existing pinned action.

  • Publish unsuccessful completed self-workflow attempts as unassigned, repository-local CI evidence; preserve actual conclusions and exact attempts.

  • Accept exact matching development-commit comments and correct nested action pin validation and container whitespace rejection. Keep registrations scoped to their actual action paths.

  • Declare both git-submodule and reusable-workflow consumption in the GDS module contract. Refresh its projection using the existing stable bundle.

  • Place the Docker publisher permission explanation inline so the pinned pedantic audit recognizes it; workflow permissions and behavior are unchanged.

[0.1.16] - 2026-09-02

  • security-bundle authenticates its exact called-workflow source fetch with

... (truncated)

Commits
  • 9231ee7 Merge pull request #98 from fix/private-security-check-identity-20260907
  • b507bbf fix(security): preserve required check names in private-free migration
  • bc9c791 Merge pull request #97 from NDDev-OpenNetwork/fix/ci-catalog-dependencies-202...
  • ce17d74 fix(ci): preserve component identities while converging dependency pins
  • 2f28c2a Merge pull request #96: advisory self-CI and catalog-only convergence
  • da0ad7c chore(gds): refresh the advisory-context projection lock
  • 1532ced fix(ci): ordinary merge without required ci-gate
  • 79a644b docs(skills): keep authored metadata mappings; native Codex discovers them
  • 80a1fbc fix(ci): converge Dependabot catalogs without pushing workflow files
  • f7e4aa8 Merge pull request #95: align organization profiles and release adoption
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…or-sarif.yml

Bumps [NDDev-OpenNetwork/ci-workflows/.github/workflows/zizmor-sarif.yml](https://github.com/nddev-opennetwork/ci-workflows) from 1ab6708b62ec7bd17f2d8a519c6fcc39edb22243 to 9231ee7421354867b0fe0e019c4e20dcce5d05e7.
- [Release notes](https://github.com/nddev-opennetwork/ci-workflows/releases)
- [Changelog](https://github.com/NDDev-OpenNetwork/ci-workflows/blob/main/CHANGELOG.md)
- [Commits](NDDev-OpenNetwork/ci-workflows@1ab6708...9231ee7)

---
updated-dependencies:
- dependency-name: NDDev-OpenNetwork/ci-workflows/.github/workflows/zizmor-sarif.yml
  dependency-version: 9231ee7421354867b0fe0e019c4e20dcce5d05e7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 10, 2026
@rldyourmnd
rldyourmnd merged commit 7b3b702 into main Sep 10, 2026
23 checks passed
@rldyourmnd
rldyourmnd deleted the dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/zizmor-sarif.yml-9231ee7421354867b0fe0e019c4e20dcce5d05e7 branch September 10, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant