Rebuild comment sync as a post-merge repair caller - #577
Conversation
Replaces the in-PR workflow_run caller: any non-Dependabot push to a Dependabot branch flips the retriggered runs' actor off dependabot[bot], lifting the Dependabot sandbox for the PR's unreviewed action bumps (verified live on basecamp-cli#566; see basecamp/.github#11). The reusable workflow now runs post-merge: on workflow-file pushes to the default branch it repairs drifted comments via a comment-only auto-merging PR — only reviewed code ever executes. Dependabot itself maintains the bare comments on its own PRs after the bare-pin restructure. Lands disabled; enabled per repo after a full-cycle exercise.
Sensitive Change Detection (shadow mode)This PR modifies control-plane files:
|
There was a problem hiding this comment.
Pull request overview
This PR refactors the Dependabot action pin comment sync workflow to run post-merge (on main workflow-file pushes) via a SHA-pinned reusable workflow in basecamp/.github, instead of running in-PR via workflow_run on Dependabot branches.
Tip
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.
Changes:
- Replace the
workflow_runtrigger on Dependabot branches with apushtrigger onmainlimited to.github/workflows/*.yml|*.yaml, keepingworkflow_dispatch. - Update the reusable workflow reference to
basecamp/.githubpinned at45d3fc9588f15d50fbccde7476418007dd19e16e. - Adjust job permissions to allow
pull-requests: writefor opening/maintaining repair PRs.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
All reported issues were addressed across 1 file
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Replaces the in-PR
workflow_runcaller with the post-merge model (basecamp/.github#11, pinned 45d3fc95): any non-Dependabot push to a Dependabot branch flips the retriggered runs' actor offdependabot[bot], lifting the Dependabot sandbox for the PR's unreviewed action bumps — verified live on #566. Post-merge, the reusable workflow repairs drifted comments via a comment-only auto-merging PR; every pin it touches is already reviewed, and nothing is ever pushed to a Dependabot branch. Dependabot maintains the bare comments on its own PRs after the bare-pin restructure (Layer 1, merged fleet-wide).The workflow entry stays disabled through this merge; repos are enabled one at a time after a full-cycle exercise (seeded drift → repair PR → held-run approval → CI → auto-merge → terminal no-op) in one repo.
Summary by cubic
Rebuilds Dependabot action pin comment sync to run post-merge on workflow-file changes, opening a comment-only repair PR that auto-merges after checks. Removes the in-PR
workflow_runpath to avoid actor flips that bypass the Dependabot sandbox; only reviewed default-branch code runs.pushonmainfor.github/workflows/*.{yml,yaml}and keepworkflow_dispatch.basecamp/.githubas a post-merge backstop; Dependabot maintains comments on its own PRs.pull-requests: write; leave the workflow disabled for staged, per-repo rollout.Written for commit 393ae01. Summary will update on new commits.