Skip to content

chore(deps): update ferrlabs/.github digest to 39502a0 - #254

Open
ferrlabs-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ferrlabs-actions
Open

ferrlabs-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ferrlabs-actions

Conversation

@ferrlabs-renovate

@ferrlabs-renovate ferrlabs-renovate Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
FerrLabs/.github (changelog) workflow digest 2ea766239502a0

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@ferrlabs-renovate
ferrlabs-renovate Bot enabled auto-merge (squash) September 6, 2026 15:02
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/renovate-rebase.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed
@github-actions

github-actions Bot commented Sep 6, 2026

Copy link
Copy Markdown

SonarQube — aucune nouvelle issue

Comparaison entre le projet bac à sable de cette PR et la branche par défaut : SonarQube Community n'analyse pas les PR, ce delta est calculé côté CI. Détail

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Uneventful: digest-only bump of FerrLabs/.github reusable workflows (2ea7662 → 15286b3), same job/input shape across all five callers. All 19 checks green.

@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 15286b3 chore(deps): update ferrlabs/.github digest to fba6f4b Sep 7, 2026
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 46c9e4e to 2b2f9ef Compare September 7, 2026 07:30
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/renovate-rebase.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: PR was rebased to a newer digest since my last approval (2ea7662 → 15286b3), now 2ea7662 → fba6f4b. Re-checked what's new in that range for FerrLabs/.github:

  • #327 (docker RUN descriptor limit) — already covered by the prior approval.
  • #330 (github actions bump) — only touches reusable-ci-rust.yml, reusable-release-rust.yml, reusable-ferrflow-release.yml (dtolnay/rust-toolchain digest bump, gated behind hashFiles('**/Cargo.toml') != ''), renovate.yml, workflow-templates/ci-rust.yml. This repo is Go-only, no Cargo.toml, so that step never runs here.
  • #334 (concurrency group disambiguation) — touches reusable-ci-node.yml and reusable-sonarqube-scan.yml. This repo's reusable-ci-go.yml call pins its internal sonar call to a separate fixed digest (2883414f...), unrelated to this bump, so no effect.

Nothing in the new range touches reusable-ci-go.yml, reusable-pr-title.yml, reusable-renovate-dispatch.yml, or reusable-security-scan.yml beyond the pin itself. All 19 checks green. Still uneventful.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 2b2f9ef to 8cb41b2 Compare September 7, 2026 08:05
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to fba6f4b chore(deps): update ferrlabs/.github digest to 539e9ac Sep 7, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/renovate-rebase.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 539e9ac chore(deps): update ferrlabs/.github digest to 84f4447 Sep 7, 2026
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 8cb41b2 to 4bc079b Compare September 7, 2026 12:17
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/renovate-rebase.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (fba6f4b → 84f4447). Two new commits in range:

  • #331 bumps the pinned FerrLabs/FerrFlow action inside reusable-ferrflow-release.yml to v7.20.1. This repo's release.yml only passes dry-run and has no Cargo.toml, so it exercises the same job path as before, just a newer action pin.
  • #335 (pnpm-version follows packageManager) only touches reusable-ci-astro.yml and reusable-ci-node.yml, neither used here.

Nothing in the new range touches the five workflows this repo calls beyond the pin bump itself. All 19 checks green. Still uneventful.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch 3 times, most recently from 6f9fa7f to af9fccf Compare September 14, 2026 12:32
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 84f4447 chore(deps): update ferrlabs/.github digest to c2ba2d8 Sep 14, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/renovate-rebase.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch 3 times, most recently from ea08575 to cff9126 Compare September 16, 2026 21:15
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to c2ba2d8 chore(deps): update ferrlabs/.github digest to 5ff5438 Sep 16, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/renovate-rebase.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (84f4447 → 5ff5438). Four new commits in FerrLabs/.github in that range:

  • #338 sccache fix — touches setup-sccache/action.yml and reusable-ci-rust.yml only. This repo is Go-only, doesn't call the rust reusable, no effect.
  • #337 FerrFlow action bump (v7.20.1 → v7.21.1) inside reusable-ferrflow-release.yml — pin-only change, same shape as previous approvals. release.yml here only passes dry-run, same job path.
  • #336 github actions bump — the only line touching a workflow this repo calls is a codeql-action/upload-sarif pin bump in reusable-security-scan.yml (5 occurrences, all pin-only). The rest of that commit (renovate.yml, reusable-docker-build.yml, scorecard.yml) isn't used here.
  • #332 pnpm v12 — touches ci-astro.yml/ci-node.yml templates only, not used here.

No input/output/behavior change to any of the five workflows this repo calls. Checks: mostly green; CI/Build, SonarQube analysis and kind smoke test were still in progress at review time with no failures reported. Still uneventful.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from cff9126 to 5c021a0 Compare September 17, 2026 11:31
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 5ff5438 chore(deps): update ferrlabs/.github digest to 9de9605 Sep 17, 2026
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 5c021a0 to 56a4cc4 Compare September 17, 2026 20:18
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (9de9605 → c4121e7). Three new commits in FerrLabs/.github:

  • #340 (efe7f970) stops running the SonarQube job on pull_request events (reusable-ci-go.yml's sonar job gains github.event_name != 'pull_request', and reusable-sonarqube-scan.yml drops its whole PR-sandbox/diff-comment path). FerrVault's ci.yml calls reusable-ci-go.yml with enable-sonar: true, so this does affect us: the SonarQube job will simply be skipped on PRs going forward (no failure), and the delta-style PR comment (the "SonarQube — aucune nouvelle issue" comment already on this thread) stops appearing on future PRs. Not breaking, just a feature going away.
  • #343 (1d44811b) re-pins the four CI reusables' internal call to reusable-sonarqube-scan.yml to that same commit — mechanical follow-up to #340, no separate effect.
  • #342 (c4121e79) changes default runner selection in reusable-docker-build.yml and adds a runner passthrough in reusable-release-rust.yml. FerrVault's release.yml calls reusable-ferrflow-release.yml directly, which doesn't call reusable-docker-build.yml (confirmed by reading it) — no effect here.

No breaking change for this repo. Checks green except CI/Lint, CI/Test, opengrep and kind-smoke-test still in progress at review time, no failures reported.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 240dc6b to 1d7dd7f Compare September 19, 2026 08:18
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to c4121e7 chore(deps): update ferrlabs/.github digest to f9fac3f Sep 19, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (c4121e7 → f9fac3f). Two new commits in FerrLabs/.github:

  • #344 (f9fac3f) sets cache-targets: false for the test/coverage jobs on self-hosted sccache runners in reusable-ci-rust.yml only. This repo is Go-only (no Cargo.toml), so reusable-ci-rust.yml is never invoked here — no effect.
  • #346 (0513b857) changes default.json (Renovate rebase behavior for the in-cluster runner config), not any of the five reusable workflows this repo calls — no effect.

No input/output/behavior change to reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, or reusable-security-scan.yml. Checks were still queued/in progress at review time with nothing failed. Still uneventful.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 1d7dd7f to 4f14687 Compare September 19, 2026 10:20
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to f9fac3f chore(deps): update ferrlabs/.github digest to c3212b1 Sep 19, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 4f14687 to 04b2922 Compare September 20, 2026 08:07
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to c3212b1 chore(deps): update ferrlabs/.github digest to b959064 Sep 20, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (f9fac3f → b959064). Two new commits in FerrLabs/.github:

  • #349 (7b18f4c) forwards the concurrency key into the nested sonar scan in reusable-ci-node.yml only.
  • #350 (b959064) repoints sccache at a renamed garage Service, touching setup-sccache/action.yml and reusable-ci-rust.yml only.

FerrVault is Go-only and calls reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml — none of which changed in this range. No effect here. Still uneventful.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 04b2922 to 7c9c36b Compare September 20, 2026 10:07
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to b959064 chore(deps): update ferrlabs/.github digest to 071c55a Sep 20, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (b959064 → 071c55a). One new commit in FerrLabs/.github:

  • #351 caps js-yaml below v5 (later narrowed to below v4, override entries only) in default.json — Renovate config only, not any of the five reusable workflows this repo calls.

No input/output/behavior change to reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, or reusable-security-scan.yml. Checks were queued/in progress at review time, nothing failed. Still uneventful.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 7c9c36b to 9b4761f Compare September 20, 2026 14:07
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 071c55a chore(deps): update ferrlabs/.github digest to af8854d Sep 20, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (071c55a → af8854d). One new commit in FerrLabs/.github:

  • #354 adds a Renovate rule in default.json exempting FerrLabs-published charts (ghcr.io/ferrlabs/charts/**) from the one-day merge delay. Renovate config only, not any of the five reusable workflows this repo calls.

No input/output/behavior change to reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, or reusable-security-scan.yml. Checks were still queued/in progress at review time, nothing failed. Still uneventful.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 9b4761f to 46dc654 Compare September 20, 2026 16:06
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to af8854d chore(deps): update ferrlabs/.github digest to 2718959 Sep 20, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (071c55a → af8854d). Three new commits in FerrLabs/.github:

  • #356 (9ae8b52) adds a CARGO_REGISTRY_TOKEN env var (from secrets.CARGO_FERRLABS_REGISTRY_TOKEN) to the FerrFlow action step in reusable-ferrflow-release.yml. FerrVault is Go-only (no Cargo.toml), so the cargo-publish path this feeds is never exercised. release.yml here uses secrets: inherit, so no new secret needs to be declared on our side either way.
  • #357 (be30e53) and #354's follow-up narrowing — Renovate config only (default.json), not any of the five reusable workflows this repo calls.
  • #358 (2718959, the new pinned digest) touches reusable-docker-build.yml only (image signing on CVE-scan failure). release.yml calls reusable-ferrflow-release.yml directly, which doesn't invoke reusable-docker-build.yml — no effect here.

No input/output/behavior change to reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, or reusable-security-scan.yml beyond the pin. Checks were still queued/in progress at review time (CI/Lint, CI/Security, CI/Test, zizmor, gitleaks, opengrep, kind-smoke-test), nothing failed. Still uneventful.

@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 2718959 chore(deps): update ferrlabs/.github digest to 39502a0 Sep 21, 2026
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 46dc654 to 88d53db Compare September 21, 2026 02:03
Comment thread .github/workflows/ci.yml
pull-requests: write
name: CI
uses: FerrLabs/.github/.github/workflows/reusable-ci-go.yml@2ea766256b2f8a92114638a0eb8f54967e9bca25 # main
uses: FerrLabs/.github/.github/workflows/reusable-ci-go.yml@39502a0fbaa351acb517c0113136c199f5e16e14 # main
scan:
name: Secrets + CVE
uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@2ea766256b2f8a92114638a0eb8f54967e9bca25 # main
uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@39502a0fbaa351acb517c0113136c199f5e16e14 # main

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up: digest moved again since my last approval (2718959 → 39502a0). Two new commits in FerrLabs/.github:

  • #359 bumps codecov/codecov-action v7.0.0 → v7.1.1 in reusable-ci-go.yml (used by this repo's ci.yml). Upload-only step with fail_ci_if_error: false, so no build-breaking risk. The rest of that commit touches reusable-ci-node.yml, reusable-ci-rust.yml, reusable-sonarqube-scan.yml and templates, none of which this repo calls (its sonarqube job in reusable-ci-go.yml pins its own digest to reusable-sonarqube-scan.yml, unchanged here).
  • #360 bumps the pinned FerrLabs/FerrFlow action v7.21.1 → v7.21.7 in reusable-ferrflow-release.yml, used by this repo's release.yml. Checked FerrFlow's own history for that range: three patch fixes (#1089 monorepo diff perf, #1094 migrate dry-run messaging, #1096 npm dev-build fallback), none touching the dry_run/force_version/bot inputs this repo's release.yml uses.

No input/output/behavior change to any of the five workflows this repo calls beyond the two pins. Checks were still queued/in progress at review time (CI/Lint, CI/Test, CI/Security, opengrep, gitleaks, zizmor, kind-smoke-test), nothing failed. Still uneventful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant