Re-pin dependabot-sync reusable workflow past the dispatch fallback - #573
Merged
Conversation
basecamp/.github#10 removed the CI-dispatch fallback (Codex P1 on fizzy-cli#189: dispatching branch workflows executes unreviewed action pins outside the Dependabot sandbox); the workflow now verifies CI started on the pushed head and warns a maintainer if not.
Sensitive Change Detection (shadow mode)This PR modifies control-plane files:
|
There was a problem hiding this comment.
Pull request overview
Updates this repo’s Dependabot-sync “thin caller” workflow to point at the newer SHA of the reusable workflow in basecamp/.github, aligning with the upstream removal of the workflow_dispatch fallback and its associated unreviewed-branch execution risk.
Changes:
- Re-pin
basecamp/.github/.github/workflows/dependabot-sync-actions-comments.ymlfrom95a9f7a…to9ca40e3….
Tip
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
basecamp/.github#10 removed the CI-dispatch fallback (valid Codex P1 on fizzy-cli#189:
gh workflow run <wf> --ref <dependabot-branch>executes the branch's freshly-bumped, unreviewed action pins outside the Dependabot-restrictedpull_requestcontext). The reusable workflow now verifies CI started on the pushed head — which deploy-key pushes trigger normally — and warns a maintainer if not, never dispatching branch workflows. Pin bump only.Summary by cubic
Re-pin the
basecamp/.githubdependabot-sync reusable workflow to commit9ca40e3to adopt the removal of the CI-dispatch fallback. This prevents unsafe branch workflow dispatches by verifying CI started on the pushed head and warning a maintainer if not.Written for commit c0b9760. Summary will update on new commits.