ci: align the Dependabot ignore for ci-workflows with the fleet decision - #125
Merged
Conversation
Widen the ignore back to melodic-software/ci-workflows/* so composites and reusables move together instead of on split cadences. Phase 6b-ii item L (melodic-software/github-iac#378) found that keeping the fleet on one ci-workflows SHA depends on composites moving by hand in the same convergence pass as reusables; narrowing this repo's ignore to only the reusable-workflow path let composite bumps drift onto Dependabot's separate weekly cadence, defeating that one-SHA guarantee. Reusable bumps to an unreviewed SHA still fail the Runner policy contract fleet-wide, so the ignore itself stays; only the glob and its comment change. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1a62500cfd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No related issue: melodic-software/github-iac#378 tracks the ci-perf program (Phase 6b-ii item L).
Summary
Widens this repo's Dependabot
ignoreformelodic-software/ci-workflowsback to the fullmelodic-software/ci-workflows/*glob, so composite actions rejoin the same manual convergencepass as reusable workflows instead of moving on Dependabot's separate weekly cadence.
Fix
.github/dependabot.ymlpreviously narrowed the ignore tomelodic-software/ci-workflows/.github/workflows/*, leaving composite-action refs undermelodic-software/ci-workflows/.github/actions/*open to Dependabot bumps. Phase 6b-ii item Lfound that a split cadence between composites (Dependabot, weekly) and reusables (manual,
per-tag) means the fleet is never on one ci-workflows SHA except by coincidence, which defeats
the program's one-SHA convergence goal. The ignore is now:
This repo runs no
Runner policylane itself, so the change is purely about the fleet carryingone answer to this question; item L found this repo's own PR (
.github#123) already moved its 14composite pin sites by hand in Step 3 without friction.
Verification
check-jsonschema --builtin-schema dependabot .github/dependabot.ymlpasses.Related
Refs melodic-software/github-iac#378