Skip to content

ci(dependabot): gate updates on exact-head checks - #142

Merged
jrandolf merged 1 commit into
mainfrom
ci-dependabot-safe-merges
Sep 24, 2026
Merged

jrandolf merged 1 commit into
mainfrom
ci-dependabot-safe-merges

Conversation

@jrandolf

Copy link
Copy Markdown
Contributor

Root cause

The repository's Dependabot workflow requested auto-merge with GITHUB_TOKEN, which can leave the merged default-branch SHA without push CI. The current main SHA 32bb6dafbae83942c964347c13151fcf2a46431e also lacks its required CodeQL summary context. On Dependabot PR #141 head f35f2c182dc23266825071f06590315387d1a0e2, the required CodeQL result is neutral, so that PR cannot be safely drained as-is.

Repair

  • .github/workflows/dependabot-automerge.yml: replace the token-driven merge request with a read-only gate. It verifies the PR still has the same exact head, requires all six existing strict contexts and every other applicable latest check to succeed, and recognizes only the docs deploy job's documented non-applicable skip on PRs. An external authenticated monitor performs the eventual merge after branch/review conditions pass.
  • .github/workflows/codeql.yml: run advanced Actions and JavaScript/TypeScript CodeQL scans for pushes and PRs, including Dependabot PRs. Default setup was changed to not-configured for advanced uploads.
  • .github/dependabot.yml: group CodeQL init/analyze updates together.

Commit: ci(dependabot): gate updates on exact-head checks (3000b70c50d49eb6f0f5b523d629f6179fc1a135). No release.

Local verification

All work and logs are under /Volumes/Code/Sources/.dev-storage/mathematic-inc-monitor/2026-09-24T162841Z-automerge on the external drive.

  • mise install; pnpm install --frozen-lockfile; pnpm typecheck; pnpm build; pnpm test after build (104 tests); pnpm pack --dry-run; pnpm audit --audit-level high: each exit 0. The Node 20.0.0 runtime smoke test and npm pack --dry-run also exited 0. Logs: logs/native/ts-japi-*.log with adjacent .exit files.
  • hk check --all --slow: exit 0 after fetching the full Git history; the rerun scanned 184 commits without secret-scan fetch warnings. git fsck --full, actionlint on changed workflows, and git diff --check: exit 0.
  • An initial test attempt before building exited 1 because this repository's test/issue-62 imports generated lib; the exact CI order builds first, and the post-build test rerun passed. The first hk run on a filtered clone emitted a Git fetch warning despite exit 0; the full-history rerun is the trusted exhaustive result.

The original six required checks remain in the branch ruleset. This PR must pass them on its exact head, including CodeQL, before any merge. The new default SHA will be audited again afterward.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@jrandolf
jrandolf merged commit 7fa505f into main Sep 24, 2026
9 checks passed
@jrandolf
jrandolf deleted the ci-dependabot-safe-merges branch September 24, 2026 18:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants