The Wire · Showcase
ELIXIR BUMPS ZIZMOR SECURITY SCANNER TO 1.28.0
By RepoJournal · Filed · About Elixir & Phoenix
The Elixir repo updated its CI security action overnight, pulling in the latest zizmor static analysis tooling.
Dependabot merged a routine dependency bump to zizmor-action, upgrading from 0.6.0 to 0.6.1 [1]. The change swaps in zizmor 1.28.0 as the default version for the GitHub Action, bringing whatever improvements and fixes that release carries to Elixir's own CI pipeline. This is a low-risk maintenance merge that keeps the language's security scanning baseline current. No breaking changes flagged, and the bump applies only to tooling, not the core language or standard library.
One email a day. Unsubscribe in one click.
Keep up with Elixir & Phoenix in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
One email a day. Unsubscribe in one click. Read a past issue →
Action items
- → Nothing to do. This is an internal Elixir repo change. elixir-lang/elixir [monitor]
References
- [1] Bump zizmorcore/zizmor-action from 0.6.0 to 0.6.1 ↗ elixir-lang/elixir