chore(deps): bump petry-projects/.github/.github/workflows/dependabot-rebase-reusable.yml from f4107cd34b06f0bef6d07b38a8bbab406830c3dc to ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da - #380
Conversation
…-rebase-reusable.yml Bumps [petry-projects/.github/.github/workflows/dependabot-rebase-reusable.yml](https://github.com/petry-projects/.github) from f4107cd34b06f0bef6d07b38a8bbab406830c3dc to ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da. - [Commits](petry-projects/.github@f4107cd...ce8a8c3) --- updated-dependencies: - dependency-name: petry-projects/.github/.github/workflows/dependabot-rebase-reusable.yml dependency-version: ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…-github/dot-github/workflows/dependabot-rebase-reusable.yml-ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 200251a44cae1593b3748db0363167b152ebe7e7
Review mode: triage-approved (single reviewer)
Summary
Dependabot bumps the org-internal reusable workflow dependabot-rebase-reusable.yml from f4107cd to ce8a8c3 (single-line, SHA-pinned ref in .github/workflows/dependabot-rebase.yml). Both old and new SHAs verified to exist in petry-projects/.github; the new head commit pins the agent-shield reusable workflow to a SHA, a security improvement. First-party reusable workflow, properly SHA-pinned.
Linked issue analysis
No linked issue (standard for a Dependabot dependency bump). N/A.
Findings
- Single +1/-1 change: updates a SHA-pinned
uses:ref for a first-party org reusable workflow. - New SHA
ce8a8c3verified present in petry-projects/.github (head commit: "fix: pin agent-shield reusable workflow to SHA (#132)"); old SHA also verified. - Ref remains pinned to a full 40-char commit SHA (not a mutable tag) — no GitHub Actions pinning regression.
- No code, secrets, or logic changes. No new third-party dependencies.
- dev-lead agent independently assessed the PR as clean (no changes needed).
CI status
All required checks green: build-and-test, Node.js Tests, Playwright UI Tests, Coverage, CodeQL (actions/js-ts/python), SonarCloud (Quality Gate passed, 0 new issues / 0 hotspots), AgentShield, Secret scan (gitleaks), npm audit. Remaining audit jobs SKIPPED (no matching ecosystem). No failures or cancellations.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.
…-github/dot-github/workflows/dependabot-rebase-reusable.yml-ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da
|
CI Failure: SonarCloud Code AnalysisStep: SonarCloud Code Analysis This is a Dependabot PR that only updates a reusable workflow SHA with no source code changes. SonarCloud analyses require the Suggested fix: Add a repository secret passthrough for Dependabot by navigating to Settings → Secrets → Dependabot and ensuring |
…-rebase-reusable.yml from f4107cd34b06f0bef6d07b38a8bbab406830c3dc to ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da (#380) chore(deps): bump petry-projects/.github/.github/workflows/dependabot-rebase-reusable.yml Bumps [petry-projects/.github/.github/workflows/dependabot-rebase-reusable.yml](https://github.com/petry-projects/.github) from f4107cd34b06f0bef6d07b38a8bbab406830c3dc to ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da. - [Commits](petry-projects/.github@f4107cd...ce8a8c3) --- updated-dependencies: - dependency-name: petry-projects/.github/.github/workflows/dependabot-rebase-reusable.yml dependency-version: ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: dependabot-automerge-petry[bot] <270452309+dependabot-automerge-petry[bot]@users.noreply.github.com>



Bumps petry-projects/.github/.github/workflows/dependabot-rebase-reusable.yml from f4107cd34b06f0bef6d07b38a8bbab406830c3dc to ce8a8c328b21feb26c7bb9ef81ffb26354e9a4da.
Commits
ce8a8c3fix: pin agent-shield reusable workflow to SHA (#132)e262589chore(deps): Bump actions/checkout from 6.0.2 to 6.0.3 (#459)6d251e1chore(deps): Bump SonarSource/sonarqube-scan-action from 8.1.0 to 8.2.0 (#460)bb7964achore(deps): Bump pnpm/action-setup from 5.0.0 to 6.0.8 (#461)897e4defix(compliance-audit): suppress gh_api stdout on failure to fix false CODEOWN...f471b21feat(feature-ideation): auto-enhance new Ideas Discussions on creation (#448)8678852chore(compliance): run re-trigger sweep hourly (one issue per repo per hour) ...73231f6fix(standards): correct SHA in dependabot-rebase template (#145)e802345feat(claude-code-reusable): enable rebases in interactive job (#235)220ee92fix: enable delete_branch_on_merge on .github repo (#222)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)