CLP-1080: Bump ci-github-actions references from v1 to v2 - #598
mary-georgiou wants to merge 3 commits into
Conversation
| env: | ||
| BUILD_NUMBER: ${{ needs.build.outputs.build-number }} |
There was a problem hiding this comment.
💡 Quality: Manual BUILD_NUMBER handoff left in place despite PR saying none exists
The PR description says no plumbing cleanup was needed. But build.yml still passes the build number by hand: outputs.build-number: steps.build.outputs.BUILD_NUMBER, plus env: BUILD_NUMBER: needs.build.outputs.build-number in build-win, qa and promote. v2 makes this redundant because get-build-number now shares the claimed number across jobs in the same run through Git refs. The equivalent v2 migration in sonar-html PR #830 removes this handoff. Nothing breaks today, but the migration is incomplete and the description is inaccurate. Remove the build-number job output and the BUILD_NUMBER env entries, or correct the description if you want to keep them.
Was this helpful? React with 👍 / 👎
guillaume-dequenne
left a comment
There was a problem hiding this comment.
Looks good overall, but I think the comment from Gitar does need to be addressed in this case.
Bumped build-maven, config-maven, promote, and pr_cleanup action refs from @v1 to @v2 across build.yml, pr-cleanup.yml, and unified-dogfooding.yml. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Mary Georgiou <89914005+mary-georgiou@users.noreply.github.com>
90b4e2a to
a496d4a
Compare
|
…-1080-bumpCiActionsV2 # Conflicts: # .github/workflows/build.yml # .github/workflows/unified-dogfooding.yml
❌ ErrorsYour PR has failed checks. Please review the issues below and take necessary action before merging. 🚦 1 Pipeline job failed
Useful? React with 👍 / 👎 This comment will be updated automatically if new data arrives.🔗 Commit SHA: f0b4596 | Docs | View more details | Give us feedback! |
CI failed: GitHub Actions workflows failed with HTTP 403 during build number generation because bumping ci-github-actions to v2 requires 'contents: write' workflow permissions.Overview1 unique configuration failure pattern was found across 2 failed logs. The failure is directly related to the pull request bumping ci-github-actions references from v1 to v2 without sufficient workflow permissions. FailuresWorkflow Permission Denied for v2 Action (confidence: high)
Summary
Code Review 👍 Approved with suggestions 1 closed / 2 findings🔴 High risk · Dogfooding workflow elevates repository contents permission to write for CI actions. Bumps 💡 Quality: Manual BUILD_NUMBER handoff left in place despite PR saying none exists📄 .github/workflows/build.yml:24-25 📄 .github/workflows/build.yml:55-56 📄 .github/workflows/build.yml:108-109 📄 .github/workflows/build.yml:160-161 The PR description says no plumbing cleanup was needed. But build.yml still passes the build number by hand: ✅ 1 closed✅ Bug: build-maven@v2 needs contents: write, but dogfooding job only has read
🤖 Prompt for agentsReview coverage🧪 Functional validation 1 of 2 objectives covered 📋 Rules No rules evaluated 🤖 Auto-approval Not enabled · Set up Implementation Status ◻️ 1 of 2 objectives covered◻️ CLP-1080 - 1 of 2 objectives coveredThis PR covers bumping the ci-github-actions references from v1 to v2. Other objectives on this issue, possibly covered elsewhere:
✅ 1 covered here
Tip Comment OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |





CLP-1080
Bumped
SonarSource/ci-github-actions/<action>@v1references to@v2in the build, PR cleanup, and unified dogfooding workflows.There is no standalone
get-build-numberrelay job in this repository.build.ymlstill passesBUILD_NUMBERfrom the build job to downstream jobs. Keep that output: the analysis job introduced by #588 uses it to download the artifact produced by the build job, and passes the same value tobuild-maven@v2.🤖 Generated with Claude Code