Skip to content

chore: bump dependabot-rebase reusable to current main SHA - #111

Closed
don-petry wants to merge 8 commits into
mainfrom
chore/bump-dependabot-rebase-sha
Closed

don-petry wants to merge 8 commits into
mainfrom
chore/bump-dependabot-rebase-sha

Conversation

@don-petry

@don-petry don-petry commented Apr 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dependabot-rebase-reusable.yml caller from the stale @v1 tag to the current main SHA of petry-projects/.github.

The @v1 tag points to an old commit that lacks:

  • Fallback @dependabot rebase comment for branches with workflow files (403 workaround)
  • Re-approval after update-branch to satisfy require_last_push_approval
  • Correct if CMD=$(cmd); then ... else ... fi pattern (bash -e bug fix)
  • contents: write + pull-requests: write job-level permissions (required for reusable to write)

This is a routine maintenance bump — no behaviour changes needed in this repo.

Summary by CodeRabbit

  • Chores
    • Updated CI/CD workflow dependency reference for improved stability and consistency.

Review Change Stack

Copilot AI review requested due to automatic review settings April 17, 2026 16:39
@coderabbitai

coderabbitai Bot commented Apr 17, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: f672d340-7973-4864-b13c-3c854dff5bfa

📥 Commits

Reviewing files that changed from the base of the PR and between 96b2c67 and d1be047.

📒 Files selected for processing (1)
  • .github/workflows/dependabot-rebase.yml

📝 Walkthrough

Walkthrough

The dependabot-rebase workflow reference is pinned from the floating @v1 tag to a specific commit SHA, ensuring deterministic workflow execution. No changes are made to the trigger events, permissions, or secrets configuration.

Changes

Dependabot Rebase Workflow

Layer / File(s) Summary
Pin reusable workflow reference
.github/workflows/dependabot-rebase.yml
The jobs.dependabot-rebase.uses reference is updated from @v1 to the pinned commit SHA @9a694e5798ebb596476e6eda80f11e832d8fd0a9 for reproducible workflow execution.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

  • petry-projects/TalkTerm#126: Pins a reusable workflow reference in agent-shield-reusable.yml from floating @v1 tag to a specific commit SHA, following the same pattern of workflow determinism.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately and concisely describes the main change: pinning the dependabot-rebase reusable workflow from a mutable tag (@v1) to a specific commit SHA.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/bump-dependabot-rebase-sha

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the Dependabot rebase workflow caller to use a pinned commit SHA of the org reusable workflow, aligning the repo with the current upstream implementation and its required permissions/secrets plumbing.

Changes:

  • Switch petry-projects/.github reusable reference from @v1 to a specific commit SHA.
  • Add workflow_dispatch to allow manual runs.
  • Update job-level permissions and switch from secrets: inherit to an explicit secrets mapping.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +45 to +47
secrets:
APP_ID: ${{ secrets.APP_ID }}
APP_PRIVATE_KEY: ${{ secrets.APP_PRIVATE_KEY }}
push:
branches:
- main
workflow_dispatch: # allow manual trigger to flush Dependabot PR queue
@don-petry

don-petry commented Apr 17, 2026 •

Copy link
Copy Markdown
Contributor Author
Outdated review (superseded by re-review at 4ba9582ea8b1346254cbf330f4048bfb59392e8d) — click to expand.

Automated review — APPROVED

Risk: MEDIUM
Reviewed commit: 62a399aa369610c2ac53470f292beda117fb89ed
Cascade: triage → deep (see triage: haiku 4.5 → deep: sonnet 4.6 + duck: gpt-5.4 → audit: opus 4.6 for models)

Summary

This PR bumps the dependabot-rebase reusable workflow from a mutable @v1 tag to a pinned SHA, which is a net security improvement. All CI checks pass (CodeQL, SonarCloud, AgentShield all green). The permission escalation (read→write) is necessary for the reusable to perform branch updates and re-approvals, and is clearly documented; the switch from secrets: inherit to an explicit secrets block is strictly more secure than the prior state.

Findings

Minor

  • [minor] .github/workflows/dependabot-rebase.yml:43 — Job permissions escalated from read to write for contents and pull-requests. This is required for the reusable to call update-branch and re-approve PRs (explained in PR body), but reviewers should confirm the GitHub App scopes are similarly scoped.

Info

  • [info] .github/workflows/dependabot-rebase.yml:47 — SHA pinning (replacing @v1 mutable tag with commit SHA 9a694e5) is a best-practice security improvement — the exact code that runs is now immutable.
  • [info] .github/workflows/dependabot-rebase.yml:49 — Switching from secrets: inherit (passes ALL secrets) to explicit APP_ID + APP_PRIVATE_KEY mapping is a least-privilege improvement.
  • [info] .github/workflows/dependabot-rebase.yml:50 — APP_PRIVATE_KEY is forwarded to the petry-projects/.github reusable. This is the same org, pinned to a verified SHA, and is no regression from the prior secrets: inherit which already passed it. The App's actual permission scope is determined by its GitHub App installation — out of scope for this diff.

CI status

All CI checks pass: CodeQL (actions+python), SonarCloud (0 issues, 0 security hotspots), AgentShield, dependency-audit. No failures or warnings.


Reviewed by the don-petry PR-review cascade (triage: haiku 4.5 → deep: sonnet 4.6 + duck: gpt-5.4 → audit: opus 4.6). Reply with @don-petry if you need a human.

@don-petry
don-petry enabled auto-merge (squash) April 17, 2026 17:40
@don-petry
don-petry disabled auto-merge April 18, 2026 18:31
@github-actions

Copy link
Copy Markdown
Contributor

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved manually.

Please resolve the conflicts and push:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

@petry-projects-pr-review-agent petry-projects-pr-review-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed by the don-petry PR-review cascade (triage: haiku 4.5 → deep: sonnet 4.6 + duck: gpt-5.4 → audit: opus 4.6). Reply with @don-petry if you need a human.

donpetry-bot
donpetry-bot previously approved these changes May 5, 2026

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed by the don-petry PR-review cascade (triage: haiku 4.5 → deep: sonnet 4.6 + duck: gpt-5.4 → audit: opus 4.6). Reply with @don-petry if you need a human.

@don-petry

Copy link
Copy Markdown
Contributor Author

@claude Please address all open review comments on this PR from CodeRabbit and Copilot.

@claude

claude Bot commented May 6, 2026 •

Copy link
Copy Markdown

Claude encountered an error —— View job


I'll analyze this and get back to you.

@don-petry
don-petry enabled auto-merge (squash) May 12, 2026 01:41
@don-petry
don-petry force-pushed the chore/bump-dependabot-rebase-sha branch from 4ba9582 to 9a557c8 Compare May 13, 2026 17:08
@don-petry
don-petry requested a review from a team as a code owner May 13, 2026 17:08
@sonarqubecloud

Copy link
Copy Markdown

donpetry-bot
donpetry-bot previously approved these changes May 14, 2026

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: 7333f60ff762a4a7b58ba3defc3ee16bbb2a8cb6
Review mode: triage-approved (single reviewer)

Summary

Single-line chore that replaces a mutable @v1 tag with an immutable SHA pin (9a694e5798ebb596476e6eda80f11e832d8fd0a9) for the petry-projects/.github dependabot-rebase reusable workflow. The change is strictly a supply-chain hardening — the same-org reusable is now locked to a verified commit rather than a moveable ref. All CI checks are green and the prior deep-cascade review at 62a399a already approved the broader workflow shape; the only delta at this HEAD is a clean merge of main.

Linked issue analysis

No linked issue declared on the PR. Acceptable for a routine maintenance bump of an org reusable — the PR body documents the upstream fixes the new SHA brings in (fallback rebase comment for workflow-file branches, re-approval after update-branch, bash -e if pattern, job-level contents:write + pull-requests:write).

Findings

Info

  • [info] .github/workflows/dependabot-rebase.yml:44 — SHA pinning (@v1 → 9a694e5798ebb596476e6eda80f11e832d8fd0a9 # main) is a best-practice supply-chain improvement: the exact reusable code that runs is now immutable. Same org (petry-projects/.github), no new permission surface introduced by this diff (the contents: write / pull-requests: write escalation was already in place from earlier commits on this branch).
  • [info] The merge commit 7333f60 is a no-op merge of main into the branch — no functional change from the previously approved 62a399a.

CI status

All required checks pass: CodeQL Analyze (actions) ✓, CodeQL Analyze (python) ✓, CodeQL ✓, CodeRabbit ✓, SonarCloud Quality Gate ✓ (0 new issues, 0 security hotspots).


Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: 54b19241fc69473134bfe2d194e47fe00ea243cc
Review mode: triage-approved (single reviewer)

Summary

Confirming the triage tier's low-risk assessment. This PR is a one-line supply-chain hardening: the petry-projects/.github dependabot-rebase reusable is repointed from the mutable @v1 tag to an immutable commit pin (9a694e5798ebb596476e6eda80f11e832d8fd0a9 # main). The functional change is identical to commit 7333f60 already APPROVED at the prior review cycle; the only delta to current HEAD 54b1924 is an additional no-op merge of main (which brings in unrelated claude.yml/dev-lead.yml housekeeping that is already on main and does not appear in this PR's diff). Nothing in the actual diff has changed since the cycle-1 approval.

Linked issue analysis

No linked issue declared, which is acceptable for a routine same-org reusable bump. The PR body adequately documents the upstream fixes the new SHA carries in (workflow-file branch rebase fallback, post-update-branch re-approval, bash -e if pattern fix, job-level contents:write + pull-requests:write).

Findings

Info

  • [info] .github/workflows/dependabot-rebase.yml:44 — @v1 → @9a694e5798ebb596476e6eda80f11e832d8fd0a9 # main is a best-practice supply-chain improvement; the exact reusable code that runs is now immutable. Same org (petry-projects/.github), no new permission surface introduced by this diff (the contents: write / pull-requests: write escalation was already in place from earlier commits on this branch and was already approved at cycle 1).
  • [info] Commits 7dda03b and 54b1924 are pure merges of main into the branch — no functional change from the previously approved 7333f60.

CI status

All required checks pass on HEAD: CodeQL ✓, Analyze (actions) ✓, Analyze (python) ✓, CodeRabbit ✓. SonarCloud Quality Gate has historically passed on this PR (0 new issues, 0 security hotspots) and is not re-run on merge-only commits. mergeStateStatus: BLOCKED reflects only the missing approving review, which this verdict provides.


Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.

@donpetry-bot
donpetry-bot dismissed their stale review May 17, 2026 06:39

Superseded by automated re-review at 54b1924.

@don-petry

Copy link
Copy Markdown
Contributor Author

@dev-lead - please fix this PR

@donpetry-bot

Copy link
Copy Markdown
Contributor

Automated review — human attention needed

This PR has been through 3 automated review cycles (cap: 3) without converging on an approval-and-merge state. Further automated review has been paused to avoid infinite loops.

Please take a look manually, or close this PR if it's no longer needed. Once a human review resolves the situation, remove the needs-human-review label and the cascade can be re-engaged on the next push.

Posted by the donpetry-bot PR-review cascade.

@don-petry

Copy link
Copy Markdown
Contributor Author

Closing due to merge conflict — re-implementing from fresh main

@don-petry don-petry closed this Jun 3, 2026
auto-merge was automatically disabled June 3, 2026 01:55

Pull request was closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-human-review Requires human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants