Skip to content

ci(dependabot): gate updates on exact-head checks - #24

Merged
jrandolf merged 1 commit into
mainfrom
ci/dependabot-strict-gate-20260924
Sep 24, 2026
Merged

jrandolf merged 1 commit into
mainfrom
ci/dependabot-strict-gate-20260924

Conversation

@jrandolf

Copy link
Copy Markdown
Contributor

Root cause

The existing Dependabot workflow requests auto-merge with its GITHUB_TOKEN. A merge by that token can suppress normal push workflows on the resulting default-branch SHA. The open softprops update, #23 at 8ab9f8e4e62730af808d973fa27ece02cae62324, has CI success but a required CodeQL result of neutral; it must not merge in that state.

Changes

  • .github/workflows/dependabot-automerge.yml: replace the write-capable merge job with a read-only exact-head gate. It requires the existing four strict contexts by name and provider, checks every applicable run, and fails closed on missing/non-successful or truncated results. The workflow never requests a merge with the repository token.
  • .github/workflows/codeql.yml: add security-extended Actions and Go analysis on PRs and pushes. Go uses autobuild so pull-request scanning covers the Go source.

Keep the original four strict checks and strict-up-to-date rule; add Strict Dependabot gate as an additional required context. The authenticated external monitor will merge only after its own final exact-head verification and will verify push CI on the new default SHA.

Local verification

On 1079e12, mise install, hk check --all --slow (including Go build, vet, race tests, and redacted full-history secret scans), explicit go test -race ./..., go build ./..., actionlint on both changed workflows, and git diff --check all exited 0 with the repository-pinned Go 1.18.10. Logs and exit-code files: /Volumes/Code/Sources/.dev-storage/mathematic-inc-monitor/2026-09-24T162841Z-automerge/logs/native/mcpr-*.

No release is requested or created.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@jrandolf
jrandolf merged commit 4138f27 into main Sep 24, 2026
7 checks passed
@jrandolf
jrandolf deleted the ci/dependabot-strict-gate-20260924 branch September 24, 2026 20:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants