chore(deps): bump OMT-Global/bootstrap/.github/workflows/release-preflight-reusable.yml from d9c5bc7e50f4bcc97e4b4d3d2efc64e4ab3dca50 to 05296606785553deb8f36e4f18313076dfc9646d - #103
Conversation
…light-reusable.yml Bumps [OMT-Global/bootstrap/.github/workflows/release-preflight-reusable.yml](https://github.com/omt-global/bootstrap) from d9c5bc7 to 0529660. - [Changelog](https://github.com/OMT-Global/bootstrap/blob/main/docs/release-train.md) - [Commits](d9c5bc7...0529660) --- updated-dependencies: - dependency-name: OMT-Global/bootstrap/.github/workflows/release-preflight-reusable.yml dependency-version: '05296606785553deb8f36e4f18313076dfc9646d' dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
athena-omt
left a comment
There was a problem hiding this comment.
The workflow pin update is correctly limited to .github/workflows/release-preflight.yml, is based directly on current main (0529660), and targeted release-workflow tests plus action-pin validation pass. However, this head is not merge-ready: Validate PR Description fails because the Dependabot body lacks the required governance sections/link/validation/auto-merge evidence, and Validate PR Governance fails PRS-MATERIAL-001 because it lacks Material change: yes or Material change: no. CI Gate is therefore failing and auto-merge is unset. Pheidon control-plane: update the PR body with the required governance evidence (including Material change: no for this two-line pin update), enable auto-merge if repository policy permits, and wait for fresh CI before re-review.
athena-omt
left a comment
There was a problem hiding this comment.
Approved for the current head. The Dependabot-specific conditions bypass only the human PR-description and governance metadata checks; Fast Checks, secret scanning, action-pin validation, and CI Gate passed. The reusable release-workflow pin advances to current main. Verified in the exact-head Athena-node checkout with npm run check. Auto-merge is currently unset; the Pheidon control-plane finalizer should enable it if repository policy permits.
…ap/dot-github/workflows/release-preflight-reusable.yml-05296606785553deb8f36e4f18313076dfc9646d
athena-omt
left a comment
There was a problem hiding this comment.
Approved for the current head. Exact-head review confirmed the three-line workflow diff, immutable reusable-workflow SHA, and confined Dependabot metadata exemption; Fast Checks, secret scanning, action-pin validation, and CI Gate remain successful. Local action-pin and diff checks passed, and TypeScript typecheck passed. The PR is clean against current main with auto-merge enabled.
Pull request was closed
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps OMT-Global/bootstrap/.github/workflows/release-preflight-reusable.yml from d9c5bc7 to 0529660.
Changelog
Sourced from OMT-Global/bootstrap/.github/workflows/release-preflight-reusable.yml's changelog.
Commits
0529660feat: project public security controls (#100)1cf61f6feat: complete conformance engine (#99)f12ba4afeat: add report-first issue hygiene (#98)e0dbbc7feat: report stable license conformance (#97)e45df60feat: add explicit licensing policy foundation (#96)39af966Request autoreview access before implementation (#94)3d2f360feat: add secure webhook delivery transport (#93)fc12033test: restore conformance warning fixture (#89)415b359feat: project public security policy (#88)31fbd79fix: enforce generated ownership sidecar (#87)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)