Skip to content

Bare pin comments: let Dependabot maintain action version comments - #142

Merged
jeremy merged 1 commit into
mainfrom
ci/bare-pin-comments
Jul 27, 2026
Merged

Bare pin comments: let Dependabot maintain action version comments#142
jeremy merged 1 commit into
mainfrom
ci/bare-pin-comments

Conversation

@jeremy

@jeremy jeremy commented Jul 27, 2026

Copy link
Copy Markdown
Member

Dependabot rewrites bare # vX.Y.Z comments on pinned uses: lines natively but cannot touch compound ones carrying a trailing # zizmor: ignore[...]. Moving each ignore to its own line directly below the pin (reason text kept, association verified under zizmor 1.28) makes Dependabot itself the comment maintainer — no push automation required on its PRs. Same restructure basecamp-sdk shipped in basecamp-sdk#458. Part of the post-merge redesign of the comment-sync program (see basecamp/.github#10 for why in-PR pushing is unsafe: a deploy-key push flips the run actor off dependabot[bot] and lifts the Dependabot sandbox for the unreviewed bumped actions).


Summary by cubic

Let Dependabot maintain action version comments by moving # zizmor: ignore[...] to its own line below each pinned uses: entry. Also update zizmorcore/zizmor-action to v0.6.0 to correctly associate standalone ignores.

  • Refactors

    • Move trailing # zizmor: ignore[...] into a standalone line directly under each uses: … # vX.Y.Z.
    • Keeps ignore reasons and avoids push automation on Dependabot PRs.
  • Dependencies

    • Bump zizmorcore/zizmor-action to v0.6.0.

Written for commit 33c9e08. Summary will update on new commits.

Review in cubic

…n comments

Dependabot rewrites bare version comments natively but cannot touch
compound ones carrying a trailing zizmor ignore. One line per pin plus a
standalone ignore below it (same restructure as basecamp-sdk#458) makes
Dependabot the first line of defense with no push automation needed on
its PRs.

Also normalizes zizmor-action to v0.6.0 so the audit runs a zizmor that
associates standalone ignore comments (the 1.23-era resolution of older
action versions does not).
Copilot AI review requested due to automatic review settings July 27, 2026 21:21
@github-actions

Copy link
Copy Markdown

Sensitive Change Detection (shadow mode)

This PR modifies control-plane files:

  • .github/workflows/ci.yml
  • .github/workflows/release.yml

Shadow mode — this check is informational only. When activated, changes to these paths will require approval from a maintainer.

@github-actions github-actions Bot added the enhancement New feature or request label Jul 27, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adjusts GitHub Actions workflow pin comments so Dependabot can natively maintain the # vX.Y.Z “bare pin” comment on uses: lines, while keeping zizmor ignore annotations intact and correctly associated.

Changes:

  • Split the compound setup-go pin comment in release.yml into a bare version comment plus a separate zizmor: ignore[...] line directly below it.
  • Bump the pinned zizmorcore/zizmor-action SHA (and version comment) in ci.yml to v0.6.0.

Tip

If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
.github/workflows/release.yml Makes the setup-go pin comment Dependabot-updatable while preserving the zizmor cache-poisoning ignore rationale.
.github/workflows/ci.yml Updates the pinned zizmor action SHA/version used for GitHub Actions auditing.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Re-trigger cubic

@jeremy
jeremy merged commit b3f969d into main Jul 27, 2026
29 checks passed
@jeremy
jeremy deleted the ci/bare-pin-comments branch July 27, 2026 21:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants