Skip to content

Bare pin comments: let Dependabot maintain action version comments - #192

Merged
jeremy merged 1 commit into
masterfrom
ci/bare-pin-comments
Jul 27, 2026
Merged

Bare pin comments: let Dependabot maintain action version comments#192
jeremy merged 1 commit into
masterfrom
ci/bare-pin-comments

Conversation

@jeremy

@jeremy jeremy commented Jul 27, 2026

Copy link
Copy Markdown
Member

Dependabot rewrites bare # vX.Y.Z comments on pinned uses: lines natively but cannot touch compound ones carrying a trailing # zizmor: ignore[...]. Moving each ignore to its own line directly below the pin (reason text kept, association verified under zizmor 1.28) makes Dependabot itself the comment maintainer — no push automation required on its PRs. Same restructure basecamp-sdk shipped in basecamp-sdk#458. Part of the post-merge redesign of the comment-sync program (see basecamp/.github#10 for why in-PR pushing is unsafe: a deploy-key push flips the run actor off dependabot[bot] and lifts the Dependabot sandbox for the unreviewed bumped actions).


Summary by cubic

Move zizmor ignores to their own lines under pinned uses: steps so Dependabot can maintain the bare # vX.Y.Z comments without push automation. In .github/workflows/release.yml, split the trailing ignore from the actions/setup-go pin (# v7.0.0) into a standalone line directly below it.

Written for commit 74a49fa. Summary will update on new commits.

Review in cubic

…n comments

Dependabot rewrites bare version comments natively but cannot touch
compound ones carrying a trailing zizmor ignore. One line per pin plus a
standalone ignore below it (same restructure as basecamp-sdk#458) makes
Dependabot the first line of defense with no push automation needed on
its PRs.

Also normalizes zizmor-action to v0.6.0 so the audit runs a zizmor that
associates standalone ignore comments (the 1.23-era resolution of older
action versions does not).
Copilot AI review requested due to automatic review settings July 27, 2026 21:21
@github-actions

Copy link
Copy Markdown

Sensitive Change Detection (shadow mode)

This PR modifies control-plane files:

  • .github/workflows/release.yml

Shadow mode — this check is informational only. When activated, changes to these paths will require approval from a maintainer.

@github-actions github-actions Bot added the enhancement New feature or request label Jul 27, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the release GitHub Actions workflow to make action pin version comments “bare” so Dependabot can maintain them automatically, while keeping zizmor ignores intact on their own line.

Tip

If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.

Changes:

  • Split the inline compound comment on actions/setup-go into a standalone # vX.Y.Z pin comment and a separate # zizmor: ignore[...] line.
  • Preserve the existing zizmor ignore reason text without altering the pinned SHA.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Re-trigger cubic

@jeremy
jeremy merged commit 6c8d31e into master Jul 27, 2026
21 checks passed
@jeremy
jeremy deleted the ci/bare-pin-comments branch July 27, 2026 21:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants