Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
104 changes: 62 additions & 42 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,43 +1,63 @@
# SPDX-License-Identifier: MPL-2.0
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"
groups:
actions:
patterns:
- "*"
open-pull-requests-limit: 2

# Rust dependencies. Keep every Cargo project in one update entry so the
# open-PR limit applies to the fleet as a whole, rather than once per bot.
# Grouping by dependency name updates a shared crate across every affected
# project in one PR instead of opening one PR per Cargo.lock.
ignore:
# HOLD: github/codeql-action at v4.38.0 (SHA-pinned). v4.38.1 fails
# GitHub workflow-startup validation estate-wide (nexia-list#100;
# SHA-form re-bump bypassed versions-scoped ignores - nexia-list#101).
# Hold until upstream clears 4.38.1 or a new release verifies green.
- dependency-name: "github/codeql-action"

- package-ecosystem: "cargo"
directories:
- "/robot-repo-automaton"
- "/shared-context"
- "/bots/echidnabot"
- "/bots/glambot"
- "/bots/rhodibot"
- "/bots/seambot"
- "/bots/sustainabot"
- "/bots/finishingbot"
- "/bots/accessibilitybot"
- "/bots/cipherbot"
- "/bots/panicbot"
schedule:
interval: "weekly"
open-pull-requests-limit: 3
groups:
fleet-dependencies:
group-by: dependency-name
{
version: 2,
updates: [
{
package-ecosystem: "github-actions",
directory: "/",
schedule: {
interval: "daily",
},
groups: {
actions: {
patterns: [
"*",
],
},
},
open-pull-requests-limit: 2,
ignore: [
# HOLD: github/codeql-action at v4.38.0 (SHA-pinned). v4.38.1 fails
# GitHub workflow-startup validation estate-wide (nexia-list#100;
# SHA-form re-bump bypassed versions-scoped ignores - nexia-list#101).
# Hold until upstream clears 4.38.1 or a new release verifies green.
{
dependency-name: "github/codeql-action",
},
],
},
# Rust dependencies. Keep every Cargo project in one update entry so the
# open-PR limit applies to the fleet as a whole, rather than once per bot.
# Grouping by dependency name updates a shared crate across every affected
# project in one PR instead of opening one PR per Cargo.lock.
#
# /bots/echidnabot is deliberately absent: it is a pinned sync of
# hyperpolymath/echidnabot (bots/echidnabot/FLEET-SYNC.json). Its dependencies
# are bumped upstream and arrive here by a pin bump, never independently;
# the Vendored bot drift workflow fails on any local edit.
{
package-ecosystem: "cargo",
directories: [
"/robot-repo-automaton",
"/shared-context",
"/bots/glambot",
"/bots/rhodibot",
"/bots/seambot",
"/bots/sustainabot",
"/bots/finishingbot",
"/bots/accessibilitybot",
"/bots/cipherbot",
"/bots/panicbot",
],
schedule: {
interval: "weekly",
},
open-pull-requests-limit: 3,
groups: {
fleet-dependencies: {
group-by: "dependency-name",
},
},
},
],
}
42 changes: 7 additions & 35 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ workflows:
- 'haskell-actions/setup@v2.12.1'
'.github/workflows/codeql.yml':
- 'actions/checkout@v7.0.1'
- 'github/codeql-action@1c5b675653bb5c22dbe9b12b556ec555138e09fd'
- 'github/codeql-action@v4.38.2'
'.github/workflows/dogfood-gate.yml':
- 'actions/checkout@v7.0.1'
- 'hyperpolymath/deed-ecosystem@main'
Expand Down Expand Up @@ -48,7 +48,7 @@ workflows:
- 'actions/checkout@v7.0.1'
- 'actions/upload-artifact@v7.0.1'
- 'dtolnay/rust-toolchain@v1'
- 'Swatinem/rust-cache@v2.9.2'
- 'swatinem/rust-cache@v2.9.2'
'.github/workflows/push-email-notify.yml':
- 'hyperpolymath/smtp-notify-action@v0.3.0'
'.github/workflows/repo-integrity-guard.yml':
Expand All @@ -61,12 +61,9 @@ workflows:
- 'hyperpolymath/standards@571cc734cd69fb846032ec77a662aa8ee4fc32cd'
'.github/workflows/supervised-fleet-scan.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/vendored-bot-drift.yml':
- 'actions/checkout@v7.0.1'
dependencies:
'Swatinem/rust-cache@v2.9.2':
ref: 'v2.9.2'
commit: 'sha1-6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
owner_id: 580492
repo_id: 298565987
'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9':
ref: '55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
Expand Down Expand Up @@ -144,36 +141,16 @@ dependencies:
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
owner_id: 47606891
repo_id: 331103973
'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63':
ref: 'b96794f015dfd88f77b49b1c93e0fa7110f94c63'
commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63'
owner_id: 9919
repo_id: 259445878
'github/codeql-action@1c5b675653bb5c22dbe9b12b556ec555138e09fd':
ref: '1c5b675653bb5c22dbe9b12b556ec555138e09fd'
commit: 'sha1-1c5b675653bb5c22dbe9b12b556ec555138e09fd'
owner_id: 9919
repo_id: 259445878
'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938':
ref: 'cdf488f595d80d6e07e03d4674febd5ab45fa938'
commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938'
owner_id: 9919
repo_id: 259445878
'github/codeql-action@v4.37.8':
ref: 'v4.37.8'
commit: 'sha1-db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28'
owner_id: 9919
repo_id: 259445878
'github/codeql-action@v4.38.0':
ref: 'v4.38.0'
commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63'
'github/codeql-action@v4.38.2':
ref: 'v4.38.2'
commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2'
owner_id: 9919
repo_id: 259445878
'haskell-actions/setup@v2.12.0':
ref: 'v2.12.0'
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
owner_id: 75048950
repo_id: 623796603
'haskell-actions/setup@v2.12.1':
ref: 'v2.12.1'
commit: 'sha1-0f7370ccbc65f22514ec3e094f6601b8d61fbbf7'
Expand Down Expand Up @@ -221,11 +198,6 @@ dependencies:
commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc'
owner_id: 67707773
repo_id: 421101922
'ossf/scorecard-action@v2.4.4':
ref: 'v2.4.4'
commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc'
owner_id: 67707773
repo_id: 421101922
'peter-evans/repository-dispatch@v4.0.1':
ref: 'v4.0.1'
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,12 +48,12 @@ jobs:
uses: actions/checkout@v7.0.1

- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)
uses: github/codeql-action/init@v4.38.2
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)
uses: github/codeql-action/analyze@v4.38.2
with:
category: "/language:${{ matrix.language }}"
2 changes: 2 additions & 0 deletions .github/workflows/e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,3 +26,5 @@ jobs:
run: bash tests/e2e.sh
- name: Verify canonical descriptile policy repair
run: bash tests/retired-descriptile-policy-test.sh
- name: Verify star-list enrollment discovery
run: bash tests/enroll-discovery-test.sh
1 change: 1 addition & 0 deletions .github/workflows/lock-sync-gate.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: Lock Sync Gate

Expand Down
2 changes: 0 additions & 2 deletions .github/workflows/panicbot-sweep.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,8 +46,6 @@ jobs:

- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@v1
with:
toolchain: master
with:
toolchain: stable

Expand Down
58 changes: 58 additions & 0 deletions .github/workflows/vendored-bot-drift.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# Vendored bot drift — bots/<bot>/ copies of standalone repositories are pinned
# syncs, not forks. This fails when a vendored copy differs from the upstream
# commit pinned in bots/<bot>/FLEET-SYNC.json (see scripts/sync-vendored-bot.sh
# and bots/echidnabot/CANONICAL_SOURCE.adoc).
name: Vendored bot drift

on:
push:
branches: [main]
pull_request:
branches: ['**']
schedule:
- cron: '17 6 * * 1'
workflow_dispatch:

permissions:
contents: read

jobs:
tool-tests:
name: sync-vendored-bot tests (planted controls)
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false
- run: bash scripts/tests/sync-vendored-bot.sh

drift:
name: echidnabot pinned to hyperpolymath/echidnabot
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false
- name: Fleet copy equals pinned upstream rev
run: bash scripts/sync-vendored-bot.sh echidnabot --check
- name: Report how far upstream main is ahead of the pin (informational)
run: |
set -euo pipefail
lock=bots/echidnabot/FLEET-SYNC.json
repo="$(jq -r .repo "$lock")"
rev="$(jq -r .rev "$lock")"
branch="$(jq -r .upstream_branch "$lock")"
tmp="$(mktemp -d)"
git init -q --bare "$tmp/up.git"
git -C "$tmp/up.git" fetch -q --no-tags --filter=blob:none "$repo" "+refs/heads/$branch:refs/heads/$branch"
ahead="$(git -C "$tmp/up.git" rev-list --count "$rev..refs/heads/$branch")"
head="$(git -C "$tmp/up.git" rev-parse "refs/heads/$branch")"
if [ "$ahead" -gt 0 ]; then
echo "::notice::echidnabot upstream $branch is $ahead commit(s) ahead of the pin ($rev -> $head). Bump with: scripts/sync-vendored-bot.sh echidnabot --sync --rev $head"
else
echo "Pin is at upstream $branch head ($head)."
fi
Loading
Loading