Repository navigation
chore(deps): update ferrlabs/.github digest to 6a248c7 - #276
ferrlabs-renovate[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Digest-only bump of FerrLabs/.github (39502a0 → e056bc5) across the four reusable workflow refs in ci.yml, pr-title.yml, release.yml, security-scan.yml.
There is exactly one commit between the two SHAs (FerrLabs/.github#361, "resolve ferrlabs-* crates from crates.io instead of Kellnr"), and it only touches default.json and snippets/deny.toml — the Renovate preset and a cargo-deny snippet. None of the four reusable workflow files this repo pins (reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml) changed content at all between the old and new digest. So there's nothing for this repo's CI to actually pick up from the bump.
Note this repo's renovate.json extends github>FerrLabs/.github unpinned, so the crates.io-vs-Kellnr resolution change already applies to FerrVault's own Renovate runs regardless of this PR — it's not gated by this digest bump.
Checks running at review time are green where completed, nothing failed.
196662c to
bb5f3d5
Compare
bb5f3d5 to
2c184e1
Compare
2c184e1 to
43e3f00
Compare
There was a problem hiding this comment.
Re-review: Renovate moved the target digest since my last approval (was 39502a0→e056bc5, now 39502a0→b6a08e6), so this is a fresh diff, not a no-op rebase.
Of the four reusable workflows this repo pins, two (reusable-pr-title.yml, reusable-security-scan.yml) are byte-identical between old and new digest. The other two have real content changes, both benign for this repo:
reusable-ci-go.yml: addedcontinue-on-error: trueto the two coverage-artifact upload steps (with a comment explaining a flaky upload shouldn't fail the gate). Only loosens a failure mode, doesn't affectci.yml'sbuild-paths/enable-sonarusage.reusable-ferrflow-release.yml: bumps the pinnedFerrLabs/FerrFlowactionv7.21.7 → v7.25.0and adds an optional tag-signing feature (newTAG_SIGNING_KEYsecret,tag_signing_key/name/emailinputs).release.yml:15-19only passesFERRLABS_DISPATCH_TOKENand sets noTAG_SIGNING_NAME/TAG_SIGNING_EMAILvars, so signing stays disabled here — no-op for this repo.
Checks completed so far (gitleaks, osv-scanner, PR title, snyk, zizmor) are all green; CI Test/Lint/Security, opengrep and the kind smoke test were still running at review time with nothing failed.
43e3f00 to
2c77bef
Compare
There was a problem hiding this comment.
Re-review: Renovate moved the target digest again since my last approval (was 39502a0→b6a08e6, now 39502a0→42a0645), so this is a new diff.
Of the four reusable workflows this repo pins, three (reusable-ci-go.yml, reusable-pr-title.yml, reusable-security-scan.yml) are byte-identical to the versions I already reviewed at b6a08e6. Only reusable-ferrflow-release.yml changed further:
- Adds an opt-in
crates-io-trusted-publishinginput plus arust-lang/crates-io-auth-actionstep, and switchesCARGO_REGISTRY_TOKENfrom the staticsecrets.CARGO_FERRLABS_REGISTRY_TOKENto that step's OIDC-minted output (only populated when the new input is true). release.yml:15-18in this repo doesn't setcrates-io-trusted-publishingand doesn't passsecrets: inheritorCARGO_FERRLABS_REGISTRY_TOKEN, soCARGO_REGISTRY_TOKENwas empty before this change and stays empty after — no-op here. This repo's.ferrflowalso setsdeferPublish: true, and crates.io publish actually happens through this repo's own.github/workflows/publish.yml, not through the reusable release workflow's token at all.
Checks on the head commit were still in progress at review time (CI, Secrets+CVE scans, kind smoke test); nothing has failed so far.
2c77bef to
eebae6a
Compare
There was a problem hiding this comment.
Re-review: target digest moved again since my last approval (was 39502a0→42a0645, now 39502a0→1a21d234c).
Only one commit separates the two: FerrLabs/.github#382, "build fuzz targets for the toolchain host, not cargo-fuzz's own triple," which touches only reusable-fuzz-rust.yml. None of the four reusable workflows this repo pins (reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml) changed. No-op for this repo.
All completed checks on the head commit are green (CI Security, gitleaks, osv-scanner, snyk, zizmor, PR title); CI Test/Lint, opengrep and the kind smoke test were still running at review time with nothing failed.
eebae6a to
868ef86
Compare
There was a problem hiding this comment.
Re-review: target digest moved again since my last approval (was 39502a0→1a21d23, now 39502a0→6b7ce7f).
One commit separates the two: FerrLabs/.github#383, "chore(renovate): resolve @FerrLabs packages from npmjs". It touches default.json plus reusable-ci-node.yml and reusable-ci-astro.yml. All four reusable workflows this repo pins (reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml) are byte-identical between the two digests, as is .github/actions/. No-op for FerrVault's CI.
As before, this repo's renovate.json extends github>FerrLabs/.github unpinned, so the npmjs preset change already applies to FerrVault's Renovate runs independently of this digest bump.
Completed checks on the head commit are green (gitleaks, osv-scanner, snyk, PR title, CI Detect Go module); CI Test/Lint/Security, opengrep, zizmor and the kind smoke test were still running at review time with nothing failed.
868ef86 to
b88de3e
Compare
There was a problem hiding this comment.
Re-review: target digest moved again since my last approval (was 39502a0→6b7ce7f, now 39502a0→30bd2ef).
Two commits separate them, both touching only default.json:
- FerrLabs/.github#385, widens the Renovate Dockerfile schedule from
before 6am on mondaytoon monday. - FerrLabs/.github#386, rewords that rule's
descriptiononly.
None of the four reusable workflows this repo pins (reusable-ci-go.yml, reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml) changed, nor did .github/actions/. No-op for FerrVault's CI. As before, this repo's renovate.json extends github>FerrLabs/.github unpinned, so the schedule change already applies to FerrVault's Renovate runs independently of this digest bump.
Completed checks on the head commit are green (gitleaks, osv-scanner, snyk, zizmor, PR title, CI Detect Go module); CI Test/Lint/Security, opengrep and the kind smoke test were still running at review time with nothing failed.
b88de3e to
50385f7
Compare
50385f7 to
a409a0f
Compare
| pull-requests: write | ||
| name: CI | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ci-go.yml@39502a0fbaa351acb517c0113136c199f5e16e14 # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ci-go.yml@6a248c75b2a72155c0573bc9f82567c6506a1a9b # main |
| scan: | ||
| name: Secrets + CVE | ||
| uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@39502a0fbaa351acb517c0113136c199f5e16e14 # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@6a248c75b2a72155c0573bc9f82567c6506a1a9b # main |
There was a problem hiding this comment.
Re-review: the target digest moved from 30bd2ef (my last approval) to 6a248c7.
There are two commits between them, and neither touches a workflow:
- FerrLabs/.github#388 changes only
.github/FUNDING.yml. - FerrLabs/.github#390 changes only
default.json(Renovate rules for @FerrLabs npm updates).
None of the four reusable workflows pinned here changed. This bump does nothing to FerrVault's CI. I did not check CI status on the head commit.
This PR contains the following updates:
39502a0→6a248c7Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.