Skip to content

Conversation

brandtkeller
Copy link
Member

@brandtkeller brandtkeller commented Aug 19, 2025

Description

Pins the goreleaser-action dependency to resolve the security finding.

Also fixes a syntax issue for the gating feature - linter run passing

alternative is we can remove the repo-gate feature - but this is a nice add for forks as accidentally running nightlies on a fork could be annoying to the DevEx.

Related Issue

Fixes https://github.com/zarf-dev/zarf/security/code-scanning/195

Checklist before merging

Signed-off-by: Brandt Keller <brandt.keller@defenseunicorns.com>
@brandtkeller brandtkeller requested review from a team as code owners August 19, 2025 23:18
@brandtkeller brandtkeller self-assigned this Aug 19, 2025
Copy link

netlify bot commented Aug 19, 2025

Deploy Preview for zarf-docs canceled.

Name Link
🔨 Latest commit 735a8f4
🔍 Latest deploy log https://app.netlify.com/projects/zarf-docs/deploys/68a50b958e04ff0008443aaf

Copy link

codecov bot commented Aug 19, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: Brandt Keller <brandt.keller@defenseunicorns.com>
@brandtkeller brandtkeller changed the title chore(deps): pin goreleaser action in nightly chore(deps): Revise nightly workflow Aug 19, 2025
@brandtkeller brandtkeller changed the title chore(deps): Revise nightly workflow chore(deps): revise nightly workflow Aug 19, 2025
@brandtkeller brandtkeller added this pull request to the merge queue Aug 20, 2025
Merged via the queue into main with commit 74c05af Aug 20, 2025
27 checks passed
@brandtkeller brandtkeller deleted the nigthly-pinned-deps branch August 20, 2025 13:16
Ansible-man pushed a commit to Ansible-man/zarf that referenced this pull request Sep 6, 2025
Signed-off-by: Brandt Keller <brandt.keller@defenseunicorns.com>
Signed-off-by: Cade Thomas <cadethomas23@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants