Is there an existing issue for this?
Current Behavior
An example of issue:
- - name: Build 馃敡 & Test 馃攳
+ - name: "Build \U0001F527 & Test \U0001F50D"
Or in my case:
jobs:
zizmor:
- name: Run zizmor 馃寛
+ name: "Run zizmor \U0001F308"
runs-on: ubuntu-latest
permissions:
security-events: write
steps:
- - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
+ - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
-
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
-
- - name: Run zizmor 馃寛
- uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
+ - name: "Run zizmor \U0001F308"
+ uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3
with:
inputs: |
.github/
Expected Behavior
Unicode characters are not replaced by their binary representation.
The line should not be updated.
Steps To Reproduce
Check this PR: https://github.com/external-secrets/external-secrets/pull/6907/changes .
It contains .updatecli/updatecli.d/github-actions.yaml.
(Current relevant content:
autodiscovery:
crawlers:
github/action:
rootdir: .github
digest: true
# The crawler resolves branch-pinned Actions to an arbitrary repository
# branch instead of advancing the configured branch.
ignore:
- actions:
actions/dependency-review-action: ''
aquasecurity/trivy-action: ''
fossas/fossa-action: ''
)
Which updates the file https://github.com/external-secrets/external-secrets/blob/main/.github/workflows/zizmor.yml as shown above.
Environment
- OS: fedora 44 based system
- updatecli: updatecli v0.120.1
Pipeline Graph
(initial part redacted)
graph TD
condition#tag{"Check if zizmorcore/zizmor-action@v0.6.2 is a tag (gittag)"}
condition#tag --> source#tag_digest
source#tag_digest(["Get latest tag for zizmorcore/zizmor-action (gittag)"])
source#tag_digest --> target#tag
target#tag("deps(github): bump Action tag for zizmorcore/zizmor-action from 3dc1ecc9bcb9e94e9b2c709687979e1298497054 to {{ source :#quot;tag_digest:#quot; }} (Pinned from {{ source :#quot;tag:#quot; }}) (yaml)")
condition#tag --> source#tag
source#tag(["Get latest tag for zizmorcore/zizmor-action (gittag)"])
source#tag --> source#tag_digest
source#tag --> target#tag
condition#tag --> target#tag
source#release_digest(["Get latest GitHub Release for zizmorcore/zizmor-action (githubrelease)"])
source#release_digest --> target#release
target#release("deps(github): bump Action release for zizmorcore/zizmor-action from 3dc1ecc9bcb9e94e9b2c709687979e1298497054 to {{ source :#quot;release_digest:#quot; }} (Pinned from {{ source :#quot;release:#quot; }}) (yaml)")
source#release(["Get latest GitHub Release for zizmorcore/zizmor-action (githubrelease)"])
source#release --> target#release
source#release --> source#release_digest
source#branch(["Get latest branch for zizmorcore/zizmor-action (gitbranch)"])
source#branch --> target#branch
target#branch("deps(github): bump Action branch for zizmorcore/zizmor-action from 3dc1ecc9bcb9e94e9b2c709687979e1298497054 to {{ source :#quot;branch_digest:#quot; }} (Pinned from {{ source :#quot;branch:#quot; }}) (yaml)")
source#branch --> source#branch_digest
source#branch_digest(["Get latest branch for zizmorcore/zizmor-action (gitbranch)"])
source#branch_digest --> target#branch
condition#branch{"Check if zizmorcore/zizmor-action@v0.6.2 is a branch (gitbranch)"}
condition#branch --> source#branch
condition#branch --> target#branch
condition#branch --> source#branch_digest
condition#release{"Check if zizmorcore/zizmor-action@v0.6.2 is a GitHub release (githubrelease)"}
condition#release --> source#release
condition#release --> target#release
condition#release --> source#release_digest
Loading
OpenTelemetry Trace
No response
Anything else?
This is similar to the closed #522 .
My question is whether we should add a test in this because it seems to be a regression or at least a non unique event.
Is there an existing issue for this?
Current Behavior
An example of issue:
Or in my case:
Expected Behavior
Unicode characters are not replaced by their binary representation.
The line should not be updated.
Steps To Reproduce
Check this PR: https://github.com/external-secrets/external-secrets/pull/6907/changes .
It contains .updatecli/updatecli.d/github-actions.yaml.
(Current relevant content:
)
Which updates the file https://github.com/external-secrets/external-secrets/blob/main/.github/workflows/zizmor.yml as shown above.
Environment
Pipeline Graph
(initial part redacted)
graph TD condition#tag{"Check if zizmorcore/zizmor-action@v0.6.2 is a tag (gittag)"} condition#tag --> source#tag_digest source#tag_digest(["Get latest tag for zizmorcore/zizmor-action (gittag)"]) source#tag_digest --> target#tag target#tag("deps(github): bump Action tag for zizmorcore/zizmor-action from 3dc1ecc9bcb9e94e9b2c709687979e1298497054 to {{ source :#quot;tag_digest:#quot; }} (Pinned from {{ source :#quot;tag:#quot; }}) (yaml)") condition#tag --> source#tag source#tag(["Get latest tag for zizmorcore/zizmor-action (gittag)"]) source#tag --> source#tag_digest source#tag --> target#tag condition#tag --> target#tag source#release_digest(["Get latest GitHub Release for zizmorcore/zizmor-action (githubrelease)"]) source#release_digest --> target#release target#release("deps(github): bump Action release for zizmorcore/zizmor-action from 3dc1ecc9bcb9e94e9b2c709687979e1298497054 to {{ source :#quot;release_digest:#quot; }} (Pinned from {{ source :#quot;release:#quot; }}) (yaml)") source#release(["Get latest GitHub Release for zizmorcore/zizmor-action (githubrelease)"]) source#release --> target#release source#release --> source#release_digest source#branch(["Get latest branch for zizmorcore/zizmor-action (gitbranch)"]) source#branch --> target#branch target#branch("deps(github): bump Action branch for zizmorcore/zizmor-action from 3dc1ecc9bcb9e94e9b2c709687979e1298497054 to {{ source :#quot;branch_digest:#quot; }} (Pinned from {{ source :#quot;branch:#quot; }}) (yaml)") source#branch --> source#branch_digest source#branch_digest(["Get latest branch for zizmorcore/zizmor-action (gitbranch)"]) source#branch_digest --> target#branch condition#branch{"Check if zizmorcore/zizmor-action@v0.6.2 is a branch (gitbranch)"} condition#branch --> source#branch condition#branch --> target#branch condition#branch --> source#branch_digest condition#release{"Check if zizmorcore/zizmor-action@v0.6.2 is a GitHub release (githubrelease)"} condition#release --> source#release condition#release --> target#release condition#release --> source#release_digestOpenTelemetry Trace
No response
Anything else?
This is similar to the closed #522 .
My question is whether we should add a test in this because it seems to be a regression or at least a non unique event.