Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 48 additions & 0 deletions .github/workflows/dependabot-sync-actions-comments.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
name: Sync Dependabot action pin comments

# Thin caller: all logic lives in basecamp/.github's reusable workflow —
# trusted default-branch code that fetches the Dependabot head branch as data
# only, rewrites stale `# vX.Y.Z` pin comments, and pushes back behind a
# compare-and-swap lease using the write deploy key scoped to this repo's
# dependabot-sync environment.

on:
workflow_run: # zizmor: ignore[dangerous-triggers] -- only the SHA-pinned reusable workflow (reviewed default-branch code) executes; the Dependabot head branch is fetched as data, never executed
workflows: [Test]
types: [completed]
branches: ["dependabot/github_actions/**"]
workflow_dispatch:
inputs:
branch:
description: Dependabot branch to sync (dependabot/github_actions/...)
required: true
type: string
e2e:
description: "E2E proof mode: expect a draft PR authored by the dispatcher on a dependabot/github_actions/e2e-proof-* branch"
required: false
default: false
type: boolean

permissions: {}

jobs:
sync:
# Defense-in-depth behind the trigger-level branches filter (which stops
# runs from being created for other branches at all); the reusable
# workflow re-checks this and everything else.
if: >-
github.event_name == 'workflow_dispatch' ||
startsWith(github.event.workflow_run.head_branch, 'dependabot/github_actions/')
Comment thread
jeremy marked this conversation as resolved.
uses: basecamp/.github/.github/workflows/dependabot-sync-actions-comments.yml@9ca40e3b2d6be769b370b7cee86e8448267c95d8
with:
ci-workflow-name: Test
branch: ${{ inputs.branch || '' }}
e2e: ${{ inputs.e2e || false }}
Comment thread
jeremy marked this conversation as resolved.
permissions:
contents: read
actions: write
pull-requests: read
# The deploy key is scoped to this repo's dependabot-sync environment
# (deployment branches: default branch only); environment secrets cannot
# be forwarded explicitly to a reusable workflow, so inherit is required.
secrets: inherit # zizmor: ignore[secrets-inherit] -- see above; the called workflow is SHA-pinned and reads only SYNC_ACTIONS_DEPLOY_KEY, gated by the dependabot-sync environment
1 change: 1 addition & 0 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
name: Security

on:
workflow_dispatch:
workflow_call:
push:
branches: [main]
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/test.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
name: CI
name: Test

on:
workflow_dispatch:
push:
branches: [main]
pull_request:
Expand Down
2 changes: 1 addition & 1 deletion go.mod
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module github.com/basecamp/hey-cli

go 1.26.1
go 1.26.5
Comment thread
jeremy marked this conversation as resolved.

require (
charm.land/bubbles/v2 v2.1.0
Expand Down
Loading