Re-pin dependabot-sync past the bot-author fix - #145
Conversation
Sensitive Change Detection (shadow mode)This PR modifies control-plane files:
|
There was a problem hiding this comment.
Pull request overview
Updates this repo’s Dependabot reusable-workflow pin so the “sync action pin comments” workflow references a basecamp/.github revision that includes the bot-author constant fix mentioned in basecamp/.github#12. This is a pin-only bump; no workflow logic or permissions are otherwise changed in this repository.
Changes:
- Re-pins
basecamp/.github/.github/workflows/dependabot-sync-actions-comments.ymlfrom45d3fc9…tofdf2ae7….
Tip
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
009fb81 to
2d63e41
Compare
basecamp/.github#12: gh reports bot PR creators as app/github-actions; the fail-closed re-verification refused auto-merge on the exercise's repair PR in basecamp-sdk. Workflow remains disabled in this repo until its rollout turn.
2d63e41 to
e0edac6
Compare
basecamp/.github#12 fixed the
app/<slug>bot-author constant that basecamp-sdk's full-cycle exercise tripped (fail-closed, auto-merge refused as designed). Pin bump only; the workflow entry remains disabled in this repo until its turn in the one-at-a-time rollout.Summary by cubic
Re-pinned the reusable
dependabot-sync-actions-commentsworkflow to the latestbasecamp/.githubversion that fixes bot-author detection (app/github-actions), and updated permissions tocontents: write. The workflow remains disabled here until its rollout turn.Written for commit e0edac6. Summary will update on new commits.