ref-version-mismatch: does it need to be this picky? #2384
|
I use version comments on my SHA-pinned actions, of course I do. I have, as a usual rule, dated the comments too, so I can when I last checked. But the ref-version-mismatch check seems really picky about that: [zizmor 1.30.1; --persona auditor] I can see that the docs talk about the possibility of dependabot not seeing the comment, which would probably be sufficient reason to have a really strict rule. This isn't currently causing me pain, because I'm currently operating in offline mode everywhere, so the check is disabled. But I'm not sure I'm happy with that choice. My question is: Is the real intent of this check closer to "version comment is identically equal to tag name" (or something similar) or is it more like "version comment starts with tag name"? |
Replies: 1 comment 1 reply
Yes, this is the reason: Dependabot and other tools (Renovate, Ratchet, etc.) are all particular about the format of the comment, and zizmor tries to honor those particularities so that the things it recommends remain compatible. (Many of those tools support updates on a schedule, so it's possible your current manual process of tracking dates could be handled by one of them instead. Not sure if that would be useful to you or not.) |
Yes, this is the reason: Dependabot and other tools (Renovate, Ratchet, etc.) are all particular about the format of the comment, and zizmor tries to honor those particularities so that the things it recommends remain compatible.
(Many of those tools support updates on a schedule, so it's possible your current manual process of tracking dates could be handled by one of them instead. Not sure if that would be useful to you or not.)