SRE-1079: Use reusable workflows and Renovate preset from hashintel/actions - #165
Conversation
Point the reusable workflows and the Renovate preset at hashintel/actions instead of hashintel/.github, and run the housekeeping workflow daily at 03:00 UTC instead of every two hours.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
PR SummaryLow Risk Overview Renovate now extends Housekeeping schedule moves from every two hours ( Reviewed by Cursor Bugbot for commit 0ddd8ac. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 0ddd8ac. Configure here.
| contents: read | ||
| id-token: write | ||
| uses: hashintel/.github/.github/workflows/housekeeping-dependencies.yml@db03b98f807376bafb54963f61090600b85125b9 # main | ||
| uses: hashintel/actions/.github/workflows/housekeeping-dependencies.yml@66c812140c0f8f4a215c5f54dce5b40b476337d8 # main |
There was a problem hiding this comment.
Private workflows break public repository CI
High Severity
The uses refs now call reusable workflows in hashintel/actions. This repository is public, and GitHub only lets public callers use reusable workflows from public repositories. hashintel/actions is not among the organization's public repos, so preflight and housekeeping fail to resolve.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit 0ddd8ac. Configure here.


Requested by Tim Diekmann · Slack thread
Before: The preflight and housekeeping workflows call reusable workflows from
hashintel/.githubatdb03b98, Renovate extendsgithub>hashintel/.github:renovate-config, and housekeeping runs every two hours (0 */2 * * *).After: The same workflows come from
hashintel/actionsat66c8121, Renovate extendsgithub>hashintel/actions:renovate-config, and housekeeping runs daily at 03:00 UTC (0 3 * * *), the same schedule ashashintel/hash.hashintel/internal-infra#374already runs this way, and Tim asked for the same setup in the other repositories.How:
uses:refs now point athashintel/actions/.github/workflows/<x>.yml@66c812140c0f8f4a215c5f54dce5b40b476337d8 # main:preflight-dependencies,preflight-pr-title,preflight-todo-comments,preflight-actionlintandhousekeeping-dependencies. Each target file is byte-identical to the file at the oldhashintel/.githubSHA, so the inputs and secrets the callers pass are unchanged.hashintel/actions. It matcheshashintel/.githubmainapart from the self-reference inmatchPackageNames.0 */2 * * *becomes0 3 * * *.hashintel/.github, so none needed updating.Validated locally with
actionlinton the three changed workflows andrenovate-config-validator(renovate 44.34.3) on.github/renovate.json.🤖 Generated with Claude Code
https://claude.ai/code/session_012vhP8cbLCbnWdQP7LLFB5A
Generated by Claude Code