Skip to content

ci: use dependabot-updatable version comments for action pins - #618

Merged
kinyoklion merged 4 commits into
mainfrom
devin/1790263896-dependabot-version-comments
Sep 24, 2026
Merged

kinyoklion merged 4 commits into
mainfrom
devin/1790263896-dependabot-version-comments

Conversation

@kinyoklion

@kinyoklion kinyoklion commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Summary

Normalizes every SHA-pinned GitHub Actions reference to the trailing-comment form Dependabot maintains, so version annotations stay correct after future bumps.

  • # https://github.com/owner/repo/releases/tag/vX.Y.Z lines above a pin are replaced by uses: owner/repo@<sha> # vX.Y.Z
  • Two unannotated actions/checkout pins in server.yml gained # v7.0.1
  • Stale # .../attest/releases/tag/v4.2.1 comments removed (the pin is already # v4.2.2) — an example of the drift this format prevents
  • ilammy/msvc-dev-cmd in .github/actions/sdk-release/action.yml changed from # v1 to # v1.13.0 to match the other pins of the same SHA
Scope notes

Comment-only change; all actions remain SHA-pinned and no workflow logic changed. Verified all .github/**/*.yml still parse and that no SHA-pinned uses: remains without a trailing version comment.

Floating major tags (actions/checkout@v7, actions/attest@v4) were tried mid-review and reverted — first-party actions stay SHA-pinned for supply-chain safety.

Left alone: references pinned to named/floating tags (launchdarkly/gh-actions/actions/contract-tests@contract-tests-v1, publish-pages@publish-pages-v1.0.2, sdk-stale.yml@main), and lint-pr-title.yml@de4859c8 — that commit has no lint-pr-title-* tag pointing at it (the only tags on it are sync-snippets-v1*), so there is no accurate version to annotate.

Link to Devin session: https://app.devin.ai/sessions/fac4a106ae4640988407ee5943b00d55
Open in Devin Desktop: https://app.devin.ai/desktop/session/fac4a106ae4640988407ee5943b00d55?variant=devin
Requested by: @kinyoklion


Note

Overview
Standardizes how third-party GitHub Actions are annotated across CI and release workflows under .github/workflows/. Separate # https://github.com/.../releases/tag/vX.Y.Z lines above uses: are removed and replaced with inline # vX.Y.Z comments on the same line as the existing SHA pins (e.g. actions/checkout, ilammy/msvc-dev-cmd, MarkusJx/install-boost).

Release jobs that call actions/attest lose redundant stale attest release-link comments; behavior and the existing # v4.2.2 pin are unchanged. No workflow inputs, job logic, or action SHAs change—only comment formatting for Dependabot-friendly version labels.

Reviewed by Cursor Bugbot for commit bf27b3b. Bugbot is set up for automated code reviews on this repo. Configure here.

Co-Authored-By: rlamb@launchdarkly.com <4955475+kinyoklion@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@devin-ai-integration

Copy link
Copy Markdown
Contributor

@cursor review

@jsonbailey
jsonbailey marked this pull request as ready for review September 24, 2026 15:33
@jsonbailey
jsonbailey requested a review from a team as a code owner September 24, 2026 15:33
Co-Authored-By: rlamb@launchdarkly.com <4955475+kinyoklion@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title ci: use dependabot-updatable version comments for action pins ci: normalize GitHub Actions dependency pins and version comments Sep 24, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit d05c36f. Configure here.

Comment thread .github/workflows/release-please.yml Outdated
kinyoklion and others added 2 commits September 24, 2026 15:49
Co-Authored-By: rlamb@launchdarkly.com <4955475+kinyoklion@users.noreply.github.com>
Co-Authored-By: rlamb@launchdarkly.com <4955475+kinyoklion@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title ci: normalize GitHub Actions dependency pins and version comments ci: use dependabot-updatable version comments for action pins Sep 24, 2026
@kinyoklion
kinyoklion merged commit 03cc58a into main Sep 24, 2026
54 checks passed
@kinyoklion
kinyoklion deleted the devin/1790263896-dependabot-version-comments branch September 24, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants