Skip to content

chore(deps): bump the github-actions group across 1 directory with 8 updates - #3317

Merged
nickboldt merged 3 commits into
mainfrom
dependabot/github_actions/github-actions-50f484c3b4
Aug 31, 2026
Merged

chore(deps): bump the github-actions group across 1 directory with 8 updates#3317
nickboldt merged 3 commits into
mainfrom
dependabot/github_actions/github-actions-50f484c3b4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 8 updates in the / directory:

Package From To
actions/checkout 6.0.2 7.0.1
actions/setup-node 6.4.0 7.0.0
actions/create-github-app-token 1.12.0 3.2.0
fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml 0.32.0 0.36.0
actions/setup-python 6.2.0 7.0.0
docker/login-action 4.1.0 4.6.0
actions/stale 10.2.0 11.0.0
dawidd6/action-download-artifact 21 23

Updates actions/checkout from 6.0.2 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/setup-node from 6.4.0 to 7.0.0

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

Updates actions/create-github-app-token from 1.12.0 to 3.2.0

Release notes

Sourced from actions/create-github-app-token's releases.

v3.2.0

3.2.0 (2026-05-12)

Features

  • add support for enterprise-level GitHub Apps (#263) (952a2a7)
  • support full repository names in repositories input (#372) (85eb8dd)

Bug Fixes

  • deps: bump @​actions/core from 3.0.0 to 3.0.1 in the production-dependencies group (#364) (43e5c34)
  • validate private-key input (#376) (f24bbd8)

v3.1.1

3.1.1 (2026-04-11)

Bug Fixes

  • improve error message when app identifier is empty (#362) (07e2b76), closes #249

v3.1.0

3.1.0 (2026-04-11)

Bug Fixes

  • deps: bump p-retry from 7.1.1 to 8.0.0 (#357) (3bbe07d)

Features

v3.0.0

3.0.0 (2026-03-14)

Bug Fixes

... (truncated)

Changelog

Sourced from actions/create-github-app-token's changelog.

Changelog

3.2.0 (2026-05-12)

Features

  • add support for enterprise-level GitHub Apps (#263) (952a2a7)
  • support full repository names in repositories input (#372) (85eb8dd)

Bug Fixes

  • deps: bump @​actions/core from 3.0.0 to 3.0.1 in the production-dependencies group (#364) (43e5c34)
  • validate private-key input (#376) (f24bbd8)
Commits
  • bcd2ba4 chore(main): release 3.2.0 (#370)
  • f24bbd8 fix: validate private-key input (#376)
  • 363531b docs: capitalize Git as a proper noun in README (#374)
  • fd28011 docs: update procedure to configure Git (#287)
  • 85eb8dd feat: support full repository names in repositories input (#372)
  • c9aabb8 build(deps-dev): bump yaml from 2.8.3 to 2.8.4 in the development-dependencie...
  • e02e816 build(deps-dev): bump undici from 7.24.6 to 8.2.0 (#366)
  • 8d835bf build(deps-dev): bump esbuild from 0.27.4 to 0.28.0 in the development-depend...
  • 952a2a7 feat: add support for enterprise-level GitHub Apps (#263)
  • 43e5c34 fix(deps): bump @​actions/core from 3.0.0 to 3.0.1 in the production-dependenc...
  • Additional commits viewable in compare view

Updates fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml from 0.32.0 to 0.36.0

Release notes

Sourced from fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml's releases.

v0.36.0

This release adds a fullsend mint delete command for tearing down GCP and Cloudflare mint infrastructure (--platform, --project/--worker-name, --preview, --dry-run, and a --yolo flag to skip the typed confirmation) — including, for the first time, durable Cloudflare Worker teardown, which previous versions refused to perform. Cloudflare mint deploys also gain --pem-dir support for bootstrapping role PEMs on both durable and preview deploys, at parity with the GCP path, and a fix to how deploy URLs are constructed: fullsend mint deploy --platform cloudflare now reads the real workers.dev subdomain from your Cloudflare account instead of guessing at a fixed URL pattern, so printed preview/durable URLs should now be correct for every account.

Per-repo installs can now store mint and inference settings (mint_url, inference.provider/project/region/wif_provider) directly in config.yaml, and per-repo status_notifications config (previously org-only) is now honored by fullsend repos migrate instead of being silently dropped. Status notifications also gain an on_failure completion mode — but note this release also changes default behavior for every existing install: a hard crash during an agent run used to leave no completion comment at all; it now posts a synthesized "Interrupted" comment, even if you haven't opted into on_failure mode.

One breaking change: fullsend poll --poll-mode has been removed entirely (no deprecated alias), as part of consolidating GitLab polling onto a single auto-promoting 5-minute schedule. If you invoke fullsend poll directly with --poll-mode, drop the flag — polling mode is now determined automatically. The shipped GitLab CI scaffold template never passed this flag, so most installs are unaffected.

Also in this release: Jira role resolution now looks up roles per-actor instead of paginating through full group membership lists, fixing a bug where large orgs could see legitimate members silently downgraded to "external" (lowest-trust) permissions past the 100th group member. Agent sandboxes now expose FULLSEND_ROLE and FULLSEND_SLUG env vars for custom skills that need to know their own harness identity.


Changelog

Features

  • 8b91b0393c7f379e1f3fe627c98d56df3899d028: feat(#2680): add mint delete command to tear down mint infrastructure (@​fullsend-ai-coder[bot])
  • 53b2f78a4ac04d45afdbcf1314b4e85e6369b40d: feat(#3376): differentiate scaffold PR titles for upgrades vs installs (@​fullsend-ai-coder[bot])
  • 87f9eca15a0fceb977b62dbefdd280cc1770d357: feat(#3697): add on_failure mode for comment.completion status notifications (@​ralphbean)
  • 7faae3c126c611303422f5b138fad30cce7fb162: feat(#4976): store mint and inference settings in per-repo config (@​fullsend-ai-coder[bot])
  • 8023f579d368f344c2c3ebd4be5eaa39d9dd5288: feat(#5632): support --pem-dir for CF mint deploy with User-Agent fix (@​fullsend-ai-coder[bot])
  • 353a8acc009f6d26ec05d5f4ffbfc0293244a0f8: feat(#5959): consolidate GitLab poll into single auto-promoting schedule (@​ggallen)
  • ebd1662be5b4b214b551300586fa9e7a5b640e78: feat(#5988): add tracker.ErrNotFound to define Client's NotFound contract (@​ralphbean)
  • c0d07a4f0d82d4a6300089769839feba243472d6: feat(#5988): introduce tracker.Client interface with forge adapter (@​ralphbean)
  • dc3a6da92617ce9955b98dfd43fb3e7d167c9c15: feat(#5994): add status_notifications support to per-repo config (@​ralphbean)
  • 4fbb05ed50f66676839425542b390c162d9c895e: feat(#6041): add per-actor role lookup to overcome group pagination cap (@​fullsend-ai-coder[bot])
  • c89d5009c9cf1cc5c692c0c1ce7cdc29917f7045: feat(#6045): expose FULLSEND_ROLE and FULLSEND_SLUG as sandbox env vars (@​fullsend-ai-coder[bot])
  • 46ee57b2e2b63fdbfffd06d51e93572fd0eb1e4c: feat(mint): add --roles flag to mint deploy --pem-dir (@​fullsend-ai-coder[bot])

Bug Fixes

  • 75a56e16d67be7f1f59c3be26b122b1bf095d9fd: fix(#3697): auto-suppress start comment when completion is on_failure (@​ralphbean)
  • 6c661469f4983377168fc87f21b374629cf56063: fix(#3697): guard against empty jobStatus in ReconcileOrphaned (@​ralphbean)
  • b95181e0226ccd215160a3d030e342307925cc5b: fix(#3697): tighten on_failure predicate and fix orphan reconciliation (@​ralphbean)
  • 44259932c9e9b667de4738660b12fbe5c9874664: fix(#5346): pass --worker-name to teardownPreview (@​fullsend-ai-coder[bot])
  • 4633d49afa62f98363f3fef235e0b9b73c6a3eb6: fix(#5988): avoid stuttered "not found: not found" in wrapNotFound (@​ralphbean)
  • 2ec6124ba834da13d4be7bd4ffb6dc937cf603c9: fix(#5988): correct GitLab UpdateComment doc claim in ForgeClient (@​ralphbean)
  • 4ebdbeaa535b1df441c50386de7fcb63c156249e: fix(#5988): give tracker.Comment/Issue.Body a named Body type (@​ralphbean)
  • 30a739bcfd4ae0fd33edc7db96124cd0692a2bb2: fix(#5988): return NotFound from FakeClient.UpdateIssueComment, add tracker NotFound tests (@​ralphbean)
  • 70a15d614cfb4c5268ca40939350aed637f2ed29: fix(#5988): validate project string, fix tracker doc inconsistencies (@​ralphbean)
  • fa34a5425e7b4f64b307af73df11cae49d2fad30: fix(#6061): use direct scaffold delivery in non-GitHub forge test (@​fullsend-ai-coder[bot])
  • 236cf9501b8cea35985463e345cc92270f1a21a2: fix(deps): update module github.com/knights-analytics/hugot to v0.7.7 (#6019) (@​renovate-fullsend[bot])
  • 2fb493a2da9a8e41825d2d9bbd4db05dde437909: fix(mint): auto-bootstrap missing durable Worker before preview deploy (@​fullsend-ai-coder[bot])
  • 3b68502c2a6e10ca9890bc00d1bc72eb8ab0146c: fix(mint): default ALLOWED_WORKFLOW_FILES=* on preview when omitted (@​fullsend-ai-coder[bot])
  • daf3f26c60f652eac6bd37840163470cbeb0dbae: fix(mint): drop --keep-vars on preview deploys to prevent cross-preview contamination (@​fullsend-ai-coder[bot])
  • 07b3438d676b07a8622971684ca8735371aa4561: fix(mint): empty bootstrap env vars and fix AWF omit-vs-default (@​fullsend-ai-coder[bot])
  • 7d03748462ee1f4d715d346740d0b3157c621d70: fix(mint): include workers.dev subdomain in preview and durable deploy URLs (@​fullsend-ai-coder[bot])
  • 39d95b7afea2a8df3a2c6b2c4a649651bc96f105: fix(mint): support clearing CF deploy env vars with empty flag values (@​fullsend-ai-coder[bot])
  • 46c5d58feae966c8eb776943df4f182cb304604c: fix(reconcile-status): use ConfigWriter.StatusNotifications() directly (@​ralphbean)
  • 082fee886b1b6e910f79079761903b0bc1d20eaa: fix: address review feedback on PR #5993 (@​fullsend-ai-coder[bot])
  • bed9407a91fb1a0e199e5fe52df316d783990e5a: fix: address review feedback on PR #5993 (@​fullsend-ai-coder[bot])
  • 19db87c1fc87e0726ecb73befc1286a3cadd5111: fix: address review feedback on PR #5997 (@​ralphbean)
  • 5e5fa44615b710342d4f5183c2d8303007a36b89: fix: address review feedback on PR #6003 (@​fullsend-ai-coder[bot])
  • ee574b351c33deeccda167e6205136a1abca5975: fix: address review feedback on PR #6003 (@​fullsend-ai-coder[bot])
  • 2bdfa17238e5cdb2778102222e6623daa91dfd11: fix: address review feedback on PR #6022 (@​fullsend-ai-coder[bot])

... (truncated)

Commits
  • 65ceb96 Merge pull request #6098 from fullsend-ai/agent/6091-jira-event-semantics
  • fc7b468 Merge pull request #6102 from fullsend-ai/agent/6092-jira-local-testing-guide
  • 7a12715 Merge pull request #6096 from fullsend-ai/agent/6089-jira-project-docs
  • 452d762 Merge pull request #6047 from fullsend-ai/renovate/registry.access.redhat.com...
  • 9d5174d Merge pull request #6021 from fullsend-ai/renovate/registry.access.redhat.com...
  • d8812d7 chore(deps): update registry.access.redhat.com/ubi10/ubi docker digest to ccb...
  • 18f8520 chore(deps): update registry.access.redhat.com/ubi10/go-toolset docker digest...
  • ddd0532 Merge pull request #5736 from fullsend-ai/feat/3697-on-failure-comment-comple...
  • 3768d43 docs(#6092): add local testing section to Jira integration guide
  • 52c4683 docs(#6091): clarify event semantics and Jira output limitations
  • Additional commits viewable in compare view

Updates actions/setup-python from 6.2.0 to 7.0.0

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

Commits

Updates docker/login-action from 4.1.0 to 4.6.0

Release notes

Sourced from docker/login-action's releases.

v4.6.0

Full Changelog: docker/login-action@v4.5.2...v4.6.0

v4.5.2

Full Changelog: docker/login-action@v4.5.1...v4.5.2

v4.5.1

Full Changelog: docker/login-action@v4.5.0...v4.5.1

v4.5.0

Full Changelog: docker/login-action@v4.4.0...v4.5.0

v4.4.0

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/login-action@v4.2.0...v4.3.0

v4.2.0

... (truncated)

Commits
  • dbcb813 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • 5bcb015 [dependabot skip] chore: update generated content
  • b30b2f2 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 9087f1e Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 0009830 [dependabot skip] chore: update generated content
  • 2325523 build(deps): bump js-yaml from 5.2.1 to 5.2.2
  • 4ec1d4a Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
  • 5fc99ba Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...
  • e512bd5 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...
  • a146c91 Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
  • Additional commits viewable in compare view

Updates actions/stale from 10.2.0 to 11.0.0

Release notes

Sourced from actions/stale's releases.

v11.0.0

What's Changed

Enhancement

Dependency Update

Full Changelog: actions/stale@v10...v11.0.0

v10.4.0

What's Changed

Bug Fix

Dependency Updates

New Contributors

Full Changelog: actions/stale@v10.3.0...v10.4.0

v10.3.0

What's Changed

Bug Fix

Dependency Updates

  • Upgrade dependencies (@​actions/core, @​octokit/plugin-retry,

…updates

Bumps the github-actions group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.1` |
| [actions/setup-node](https://github.com/actions/setup-node) | `6.4.0` | `7.0.0` |
| [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `1.12.0` | `3.2.0` |
| [fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml](https://github.com/fullsend-ai/fullsend) | `0.32.0` | `0.36.0` |
| [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `7.0.0` |
| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |
| [actions/stale](https://github.com/actions/stale) | `10.2.0` | `11.0.0` |
| [dawidd6/action-download-artifact](https://github.com/dawidd6/action-download-artifact) | `21` | `23` |



Updates `actions/checkout` from 6.0.2 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@de0fac2...3d3c42e)

Updates `actions/setup-node` from 6.4.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@48b55a0...8207627)

Updates `actions/create-github-app-token` from 1.12.0 to 3.2.0
- [Release notes](https://github.com/actions/create-github-app-token/releases)
- [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md)
- [Commits](actions/create-github-app-token@d72941d...bcd2ba4)

Updates `fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml` from 0.32.0 to 0.36.0
- [Release notes](https://github.com/fullsend-ai/fullsend/releases)
- [Commits](fullsend-ai/fullsend@3cfa255...65ceb96)

Updates `actions/setup-python` from 6.2.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@a309ff8...5fda3b9)

Updates `docker/login-action` from 4.1.0 to 4.6.0
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@4907a6d...dbcb813)

Updates `actions/stale` from 10.2.0 to 11.0.0
- [Release notes](https://github.com/actions/stale/releases)
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)
- [Commits](actions/stale@b5d41d4...4391f3d)

Updates `dawidd6/action-download-artifact` from 21 to 23
- [Release notes](https://github.com/dawidd6/action-download-artifact/releases)
- [Commits](dawidd6/action-download-artifact@b6e2e70...57aa996)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/create-github-app-token
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/login-action
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/stale
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: dawidd6/action-download-artifact
  dependency-version: '23'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 18, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 18, 2026
@openshift-ci

openshift-ci Bot commented Aug 18, 2026

Copy link
Copy Markdown

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a redhat-developer member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@durandom

Copy link
Copy Markdown
Member

Overlap note vs #3476

This PR's fullsend.yaml hunk only retargets the existing shim pin (v0.32.0v0.36.0 SHA). That is not a fullsend scaffold upgrade: it keeps the old workflow template and does not add prioritize.yml, the v0.37 shim fields, or the ADR 0064 .fullsend/customized/ cleanup.

Please merge #3476 for the fullsend bump (it goes to v0.37.0). After that, rebase this Dependabot PR — the fullsend.yaml hunk should drop, and the remaining GitHub Action updates can land on their own.

Do not merge this PR as a substitute for fullsend-ai/fullsend#3476.

Align the Dependabot github-actions PR with the current fullsend tag. This is still only a SHA pin on the existing shim; the scaffold upgrade remains in #3476.

Co-authored-by: Cursor <cursoragent@cursor.com>
@openshift-ci

openshift-ci Bot commented Aug 31, 2026

Copy link
Copy Markdown

rebase

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@durandom

Copy link
Copy Markdown
Member

Pushed a follow-up to this branch: the fullsend.yaml pin is now v0.37.0 (84c8bbb), same tag as fullsend-ai/fullsend#3476.

This is still only a SHA bump on the old shim. Merge fullsend-ai/fullsend#3476 for the scaffold upgrade (prioritize.yml, template refresh, customized/ cleanup). After that, rebase this PR so the fullsend.yaml hunk drops.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 31, 2026

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure · Started 1:00 PM UTC · Completed 1:02 PM UTC

Commit: 1638dad · View workflow run →

Runtime: claude · Model: opus → claude-opus-5

@sonarqubecloud

Copy link
Copy Markdown

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 31, 2026

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure · Started 1:15 PM UTC · Completed 1:17 PM UTC

Commit: 8e88c30 · View workflow run →

Runtime: claude · Model: opus → claude-opus-5

@nickboldt nickboldt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

probably fine now

/lgtm
/approve
/publish

@nickboldt
nickboldt merged commit b5b3956 into main Aug 31, 2026
54 of 55 checks passed
@nickboldt
nickboldt deleted the dependabot/github_actions/github-actions-50f484c3b4 branch August 31, 2026 13:37
@fullsend-ai-retro

fullsend-ai-retro Bot commented Aug 31, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 1:38 PM UTC · Completed 1:49 PM UTC

Commit: 8e88c30 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.10

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR fullsend-ai/fullsend#3317 — Dependabot GitHub Actions bump

PR #3317 was a Dependabot PR bumping 8 GitHub Actions dependencies (including several major version bumps) across 24 workflow files. A human contributor (durandom) also pushed a commit bumping the fullsend reusable-dispatch pin to v0.37.0.

Timeline

  1. Aug 18 — Dependabot opened the PR. Prow bot requested /ok-to-test from an org member.
  2. Aug 31 12:21 — durandom identified overlap with PR Review agent should detect and flag PRs modifying deprecated internal/scaffold/fullsend-repo/ paths fullsend-ai/fullsend#3476 (fullsend scaffold upgrade) and pushed a commit bumping the fullsend.yaml pin to v0.37.0.
  3. Aug 31 13:00–13:02 — First review agent run (33394557338) failed: policy_denied API error from claude-opus-5 on Vertex AI. Zero tokens processed across 2 iterations.
  4. Aug 31 13:15–13:17 — Second review agent run (33395911446) failed with the same policy_denied error. Zero tokens, no review performed.
  5. Aug 31 13:17 — nickboldt approved the mechanical changes and merged the PR.

Analysis

The review agent never performed any work — both runs hit policy_denied before processing a single token. The harness retry loop classified the error as unknown and retried without success. The status comments posted were "Finished Review - Failure" without indicating that no review was actually performed. The PR was merged based solely on human review of the mechanical dependency bumps.

The agents repo is fullsend-ai/agents@v0.37.0 (resolved from .fullsend/config.yaml).

No novel proposals

All improvement opportunities identified are covered by existing open issues:

  • fullsend-ai/agents#1117 — Directly covers this incident: the opus alias resolved to a policy-denied claude-opus-5 on Vertex AI. This PR's two failed review runs are additional evidence of the same outage pattern.
  • fullsend-ai/fullsend#5295 / #5185 — This retro dispatch on a bot-authored PR with zero agent involvement (review agent processed zero tokens) is a direct waste case for the skip-retro-for-bot-PRs proposals.
  • fullsend-ai/fullsend#5382 — The status comment said "Finished Review - Failure" without classifying it as an infrastructure failure or indicating no review work was done. This is exactly the gap Status comment should classify infrastructure failures and suggest retry fullsend-ai/fullsend#5382 targets.
  • fullsend-ai/fullsend#2058 — The harness retried policy_denied errors (classified as unknown) when they were non-transient within the retry window. Evidence for fail-fast on authentication/policy errors.
  • fullsend-ai/fullsend#4796 — Even without the API failure, running a full review agent on a mechanical Dependabot GitHub Actions bump across 24 workflow files is low-value. Evidence for minimizing review effort on bot dependency PRs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code lgtm needs-ok-to-test non-workspace-changes PR changes files outside workspace directories

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants