chore(deps): update ferrlabs/.github digest to 39502a0 - #254
ferrlabs-renovate[bot] wants to merge 1 commit into
Conversation
SonarQube — aucune nouvelle issueComparaison entre le projet bac à sable de cette PR et la branche par défaut : SonarQube Community n'analyse pas les PR, ce delta est calculé côté CI. Détail |
46c9e4e to
2b2f9ef
Compare
There was a problem hiding this comment.
Follow-up: PR was rebased to a newer digest since my last approval (2ea7662 → 15286b3), now 2ea7662 → fba6f4b. Re-checked what's new in that range for FerrLabs/.github:
- #327 (docker RUN descriptor limit) — already covered by the prior approval.
- #330 (github actions bump) — only touches
reusable-ci-rust.yml,reusable-release-rust.yml,reusable-ferrflow-release.yml(dtolnay/rust-toolchain digest bump, gated behindhashFiles('**/Cargo.toml') != ''),renovate.yml,workflow-templates/ci-rust.yml. This repo is Go-only, noCargo.toml, so that step never runs here. - #334 (concurrency group disambiguation) — touches
reusable-ci-node.ymlandreusable-sonarqube-scan.yml. This repo'sreusable-ci-go.ymlcall pins its internal sonar call to a separate fixed digest (2883414f...), unrelated to this bump, so no effect.
Nothing in the new range touches reusable-ci-go.yml, reusable-pr-title.yml, reusable-renovate-dispatch.yml, or reusable-security-scan.yml beyond the pin itself. All 19 checks green. Still uneventful.
2b2f9ef to
8cb41b2
Compare
8cb41b2 to
4bc079b
Compare
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (fba6f4b → 84f4447). Two new commits in range:
- #331 bumps the pinned
FerrLabs/FerrFlowaction insidereusable-ferrflow-release.ymlto v7.20.1. This repo'srelease.ymlonly passesdry-runand has noCargo.toml, so it exercises the same job path as before, just a newer action pin. - #335 (pnpm-version follows packageManager) only touches
reusable-ci-astro.ymlandreusable-ci-node.yml, neither used here.
Nothing in the new range touches the five workflows this repo calls beyond the pin bump itself. All 19 checks green. Still uneventful.
6f9fa7f to
af9fccf
Compare
ea08575 to
cff9126
Compare
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (84f4447 → 5ff5438). Four new commits in FerrLabs/.github in that range:
- #338 sccache fix — touches
setup-sccache/action.ymlandreusable-ci-rust.ymlonly. This repo is Go-only, doesn't call the rust reusable, no effect. - #337 FerrFlow action bump (v7.20.1 → v7.21.1) inside
reusable-ferrflow-release.yml— pin-only change, same shape as previous approvals.release.ymlhere only passesdry-run, same job path. - #336 github actions bump — the only line touching a workflow this repo calls is a
codeql-action/upload-sarifpin bump inreusable-security-scan.yml(5 occurrences, all pin-only). The rest of that commit (renovate.yml,reusable-docker-build.yml,scorecard.yml) isn't used here. - #332 pnpm v12 — touches
ci-astro.yml/ci-node.ymltemplates only, not used here.
No input/output/behavior change to any of the five workflows this repo calls. Checks: mostly green; CI/Build, SonarQube analysis and kind smoke test were still in progress at review time with no failures reported. Still uneventful.
cff9126 to
5c021a0
Compare
5c021a0 to
56a4cc4
Compare
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (9de9605 → c4121e7). Three new commits in FerrLabs/.github:
- #340 (efe7f970) stops running the SonarQube job on
pull_requestevents (reusable-ci-go.yml's sonar job gainsgithub.event_name != 'pull_request', andreusable-sonarqube-scan.ymldrops its whole PR-sandbox/diff-comment path). FerrVault'sci.ymlcallsreusable-ci-go.ymlwithenable-sonar: true, so this does affect us: the SonarQube job will simply be skipped on PRs going forward (no failure), and the delta-style PR comment (the "SonarQube — aucune nouvelle issue" comment already on this thread) stops appearing on future PRs. Not breaking, just a feature going away. - #343 (1d44811b) re-pins the four CI reusables' internal call to
reusable-sonarqube-scan.ymlto that same commit — mechanical follow-up to #340, no separate effect. - #342 (c4121e79) changes default runner selection in
reusable-docker-build.ymland adds arunnerpassthrough inreusable-release-rust.yml. FerrVault'srelease.ymlcallsreusable-ferrflow-release.ymldirectly, which doesn't callreusable-docker-build.yml(confirmed by reading it) — no effect here.
No breaking change for this repo. Checks green except CI/Lint, CI/Test, opengrep and kind-smoke-test still in progress at review time, no failures reported.
240dc6b to
1d7dd7f
Compare
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (c4121e7 → f9fac3f). Two new commits in FerrLabs/.github:
- #344 (f9fac3f) sets
cache-targets: falsefor the test/coverage jobs on self-hosted sccache runners inreusable-ci-rust.ymlonly. This repo is Go-only (noCargo.toml), soreusable-ci-rust.ymlis never invoked here — no effect. - #346 (0513b857) changes
default.json(Renovate rebase behavior for the in-cluster runner config), not any of the five reusable workflows this repo calls — no effect.
No input/output/behavior change to reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, or reusable-security-scan.yml. Checks were still queued/in progress at review time with nothing failed. Still uneventful.
1d7dd7f to
4f14687
Compare
4f14687 to
04b2922
Compare
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (f9fac3f → b959064). Two new commits in FerrLabs/.github:
- #349 (7b18f4c) forwards the concurrency key into the nested sonar scan in
reusable-ci-node.ymlonly. - #350 (b959064) repoints sccache at a renamed garage Service, touching
setup-sccache/action.ymlandreusable-ci-rust.ymlonly.
FerrVault is Go-only and calls reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml — none of which changed in this range. No effect here. Still uneventful.
04b2922 to
7c9c36b
Compare
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (b959064 → 071c55a). One new commit in FerrLabs/.github:
- #351 caps
js-yamlbelow v5 (later narrowed to below v4, override entries only) indefault.json— Renovate config only, not any of the five reusable workflows this repo calls.
No input/output/behavior change to reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, or reusable-security-scan.yml. Checks were queued/in progress at review time, nothing failed. Still uneventful.
7c9c36b to
9b4761f
Compare
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (071c55a → af8854d). One new commit in FerrLabs/.github:
- #354 adds a Renovate rule in
default.jsonexempting FerrLabs-published charts (ghcr.io/ferrlabs/charts/**) from the one-day merge delay. Renovate config only, not any of the five reusable workflows this repo calls.
No input/output/behavior change to reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, or reusable-security-scan.yml. Checks were still queued/in progress at review time, nothing failed. Still uneventful.
9b4761f to
46dc654
Compare
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (071c55a → af8854d). Three new commits in FerrLabs/.github:
- #356 (9ae8b52) adds a
CARGO_REGISTRY_TOKENenv var (fromsecrets.CARGO_FERRLABS_REGISTRY_TOKEN) to the FerrFlow action step inreusable-ferrflow-release.yml. FerrVault is Go-only (noCargo.toml), so the cargo-publish path this feeds is never exercised.release.ymlhere usessecrets: inherit, so no new secret needs to be declared on our side either way. - #357 (be30e53) and #354's follow-up narrowing — Renovate config only (
default.json), not any of the five reusable workflows this repo calls. - #358 (2718959, the new pinned digest) touches
reusable-docker-build.ymlonly (image signing on CVE-scan failure).release.ymlcallsreusable-ferrflow-release.ymldirectly, which doesn't invokereusable-docker-build.yml— no effect here.
No input/output/behavior change to reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, or reusable-security-scan.yml beyond the pin. Checks were still queued/in progress at review time (CI/Lint, CI/Security, CI/Test, zizmor, gitleaks, opengrep, kind-smoke-test), nothing failed. Still uneventful.
46dc654 to
88d53db
Compare
| pull-requests: write | ||
| name: CI | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ci-go.yml@2ea766256b2f8a92114638a0eb8f54967e9bca25 # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ci-go.yml@39502a0fbaa351acb517c0113136c199f5e16e14 # main |
| scan: | ||
| name: Secrets + CVE | ||
| uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@2ea766256b2f8a92114638a0eb8f54967e9bca25 # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@39502a0fbaa351acb517c0113136c199f5e16e14 # main |
There was a problem hiding this comment.
Follow-up: digest moved again since my last approval (2718959 → 39502a0). Two new commits in FerrLabs/.github:
- #359 bumps
codecov/codecov-actionv7.0.0 → v7.1.1 inreusable-ci-go.yml(used by this repo'sci.yml). Upload-only step withfail_ci_if_error: false, so no build-breaking risk. The rest of that commit touchesreusable-ci-node.yml,reusable-ci-rust.yml,reusable-sonarqube-scan.ymland templates, none of which this repo calls (itssonarqubejob inreusable-ci-go.ymlpins its own digest toreusable-sonarqube-scan.yml, unchanged here). - #360 bumps the pinned
FerrLabs/FerrFlowaction v7.21.1 → v7.21.7 inreusable-ferrflow-release.yml, used by this repo'srelease.yml. Checked FerrFlow's own history for that range: three patch fixes (#1089 monorepo diff perf, #1094 migrate dry-run messaging, #1096 npm dev-build fallback), none touching thedry_run/force_version/botinputs this repo'srelease.ymluses.
No input/output/behavior change to any of the five workflows this repo calls beyond the two pins. Checks were still queued/in progress at review time (CI/Lint, CI/Test, CI/Security, opengrep, gitleaks, zizmor, kind-smoke-test), nothing failed. Still uneventful.
This PR contains the following updates:
2ea7662→39502a0Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.