This new version of zizmor-action brings two major changes:
-
The new
fail-on-no-inputsoption can be used to control whether
zizmor-actionfails if no inputs were collected byzizmor. The default
remainstrue, reflecting the pre-existing behavior. -
The action's use of the official
zizmorDocker images is now fully
hash-checked internally, preventing accidental or malicious modification
to the images. This also means that subsequent releases ofzizmor
will induce a release of this action, rather than the action always picking
up the latest version by default.
What's Changed
- docs: extended permissions required for internal repos by @AntoineSebert in #61
- docs: clarify description of "token" to indicate it is only used for online audits by @rmuir in #63
- Hash-check zizmor Docker images by @woodruffw in #68
- Add
fail-on-no-inputsoption by @woodruffw in #67
New Contributors
- @AntoineSebert made their first contribution in #61
- @rmuir made their first contribution in #63
Full Changelog: v0.3.0...v0.4.0