Skip to content

chore(deps): update ferrlabs/.github digest to 6a248c7 - #276

Open
ferrlabs-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ferrlabs-actions
Open

ferrlabs-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ferrlabs-actions

Conversation

@ferrlabs-renovate

@ferrlabs-renovate ferrlabs-renovate Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
FerrLabs/.github (changelog) workflow digest 39502a0 → 6a248c7

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@ferrlabs-renovate
ferrlabs-renovate Bot enabled auto-merge (squash) September 21, 2026 20:14
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Digest-only bump of FerrLabs/.github (39502a0 → e056bc5) across the four reusable workflow refs in ci.yml, pr-title.yml, release.yml, security-scan.yml.

There is exactly one commit between the two SHAs (FerrLabs/.github#361, "resolve ferrlabs-* crates from crates.io instead of Kellnr"), and it only touches default.json and snippets/deny.toml — the Renovate preset and a cargo-deny snippet. None of the four reusable workflow files this repo pins (reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml) changed content at all between the old and new digest. So there's nothing for this repo's CI to actually pick up from the bump.

Note this repo's renovate.json extends github>FerrLabs/.github unpinned, so the crates.io-vs-Kellnr resolution change already applies to FerrVault's own Renovate runs regardless of this PR — it's not gated by this digest bump.

Checks running at review time are green where completed, nothing failed.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 196662c to bb5f3d5 Compare September 22, 2026 22:08
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to e056bc5 chore(deps): update ferrlabs/.github digest to d451f1d Sep 22, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from bb5f3d5 to 2c184e1 Compare September 23, 2026 00:07
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to d451f1d chore(deps): update ferrlabs/.github digest to 006179d Sep 23, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 2c184e1 to 43e3f00 Compare September 24, 2026 08:02
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 006179d chore(deps): update ferrlabs/.github digest to b6a08e6 Sep 24, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review: Renovate moved the target digest since my last approval (was 39502a0→e056bc5, now 39502a0→b6a08e6), so this is a fresh diff, not a no-op rebase.

Of the four reusable workflows this repo pins, two (reusable-pr-title.yml, reusable-security-scan.yml) are byte-identical between old and new digest. The other two have real content changes, both benign for this repo:

  • reusable-ci-go.yml: added continue-on-error: true to the two coverage-artifact upload steps (with a comment explaining a flaky upload shouldn't fail the gate). Only loosens a failure mode, doesn't affect ci.yml's build-paths/enable-sonar usage.
  • reusable-ferrflow-release.yml: bumps the pinned FerrLabs/FerrFlow action v7.21.7 → v7.25.0 and adds an optional tag-signing feature (new TAG_SIGNING_KEY secret, tag_signing_key/name/email inputs). release.yml:15-19 only passes FERRLABS_DISPATCH_TOKEN and sets no TAG_SIGNING_NAME/TAG_SIGNING_EMAIL vars, so signing stays disabled here — no-op for this repo.

Checks completed so far (gitleaks, osv-scanner, PR title, snyk, zizmor) are all green; CI Test/Lint/Security, opengrep and the kind smoke test were still running at review time with nothing failed.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 43e3f00 to 2c77bef Compare September 24, 2026 10:01
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to b6a08e6 chore(deps): update ferrlabs/.github digest to 42a0645 Sep 24, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review: Renovate moved the target digest again since my last approval (was 39502a0→b6a08e6, now 39502a0→42a0645), so this is a new diff.

Of the four reusable workflows this repo pins, three (reusable-ci-go.yml, reusable-pr-title.yml, reusable-security-scan.yml) are byte-identical to the versions I already reviewed at b6a08e6. Only reusable-ferrflow-release.yml changed further:

  • Adds an opt-in crates-io-trusted-publishing input plus a rust-lang/crates-io-auth-action step, and switches CARGO_REGISTRY_TOKEN from the static secrets.CARGO_FERRLABS_REGISTRY_TOKEN to that step's OIDC-minted output (only populated when the new input is true).
  • release.yml:15-18 in this repo doesn't set crates-io-trusted-publishing and doesn't pass secrets: inherit or CARGO_FERRLABS_REGISTRY_TOKEN, so CARGO_REGISTRY_TOKEN was empty before this change and stays empty after — no-op here. This repo's .ferrflow also sets deferPublish: true, and crates.io publish actually happens through this repo's own .github/workflows/publish.yml, not through the reusable release workflow's token at all.

Checks on the head commit were still in progress at review time (CI, Secrets+CVE scans, kind smoke test); nothing has failed so far.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 2c77bef to eebae6a Compare September 24, 2026 12:00
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 42a0645 chore(deps): update ferrlabs/.github digest to 1a21d23 Sep 24, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review: target digest moved again since my last approval (was 39502a0→42a0645, now 39502a0→1a21d234c).

Only one commit separates the two: FerrLabs/.github#382, "build fuzz targets for the toolchain host, not cargo-fuzz's own triple," which touches only reusable-fuzz-rust.yml. None of the four reusable workflows this repo pins (reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml) changed. No-op for this repo.

All completed checks on the head commit are green (CI Security, gitleaks, osv-scanner, snyk, zizmor, PR title); CI Test/Lint, opengrep and the kind smoke test were still running at review time with nothing failed.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from eebae6a to 868ef86 Compare September 27, 2026 12:14
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 1a21d23 chore(deps): update ferrlabs/.github digest to 6b7ce7f Sep 27, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review: target digest moved again since my last approval (was 39502a0→1a21d23, now 39502a0→6b7ce7f).

One commit separates the two: FerrLabs/.github#383, "chore(renovate): resolve @FerrLabs packages from npmjs". It touches default.json plus reusable-ci-node.yml and reusable-ci-astro.yml. All four reusable workflows this repo pins (reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml) are byte-identical between the two digests, as is .github/actions/. No-op for FerrVault's CI.

As before, this repo's renovate.json extends github>FerrLabs/.github unpinned, so the npmjs preset change already applies to FerrVault's Renovate runs independently of this digest bump.

Completed checks on the head commit are green (gitleaks, osv-scanner, snyk, PR title, CI Detect Go module); CI Test/Lint/Security, opengrep, zizmor and the kind smoke test were still running at review time with nothing failed.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 868ef86 to b88de3e Compare September 28, 2026 18:12
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 6b7ce7f chore(deps): update ferrlabs/.github digest to 30bd2ef Sep 28, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review: target digest moved again since my last approval (was 39502a0→6b7ce7f, now 39502a0→30bd2ef).

Two commits separate them, both touching only default.json:

None of the four reusable workflows this repo pins (reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml) changed, nor did .github/actions/. No-op for FerrVault's CI. As before, this repo's renovate.json extends github>FerrLabs/.github unpinned, so the schedule change already applies to FerrVault's Renovate runs independently of this digest bump.

Completed checks on the head commit are green (gitleaks, osv-scanner, snyk, zizmor, PR title, CI Detect Go module); CI Test/Lint/Security, opengrep and the kind smoke test were still running at review time with nothing failed.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from b88de3e to 50385f7 Compare October 1, 2026 14:21
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to 30bd2ef chore(deps): update ferrlabs/.github digest to dc37316 Oct 1, 2026
Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/security-scan.yml Fixed
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/ferrlabs-actions branch from 50385f7 to a409a0f Compare October 6, 2026 06:13
@ferrlabs-renovate ferrlabs-renovate Bot changed the title chore(deps): update ferrlabs/.github digest to dc37316 chore(deps): update ferrlabs/.github digest to 6a248c7 Oct 6, 2026
Comment thread .github/workflows/ci.yml
pull-requests: write
name: CI
uses: FerrLabs/.github/.github/workflows/reusable-ci-go.yml@39502a0fbaa351acb517c0113136c199f5e16e14 # main
uses: FerrLabs/.github/.github/workflows/reusable-ci-go.yml@6a248c75b2a72155c0573bc9f82567c6506a1a9b # main
scan:
name: Secrets + CVE
uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@39502a0fbaa351acb517c0113136c199f5e16e14 # main
uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@6a248c75b2a72155c0573bc9f82567c6506a1a9b # main

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review: the target digest moved from 30bd2ef (my last approval) to 6a248c7.

There are two commits between them, and neither touches a workflow:

None of the four reusable workflows pinned here changed. This bump does nothing to FerrVault's CI. I did not check CI status on the head commit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant