Skip to content

chore(actions): bump three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml from 1.15.0 to 1.16.1 - #780

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/three-cubes/tc-pipelines/dot-github/workflows/python-quality-gate.yml-1.16.1
Open

chore(actions): bump three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml from 1.15.0 to 1.16.1#780
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/three-cubes/tc-pipelines/dot-github/workflows/python-quality-gate.yml-1.16.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown
Contributor

Bumps three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml from 1.15.0 to 1.16.1.

Release notes

Sourced from three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml's releases.

v1.16.1

fix(auto-merge): pass -R to gh pr merge so auto-merge actually arms (no more fatal: not a git repository in the workflow_run context). Fleet fix — repin auto-merge.yml consumers to this tag.

v1.16.0 — auto-merge resolves PR from head-sha

Fixed

  • auto-merge-on-green.yml resolves the PR from head-sha internally. A workflow_run caller has no github.event.pull_request, so callers previously ran a local resolve job to map commit→PR via commits/{sha}/pulls — but that job used the default GITHUB_TOKEN (contents: read), so the lookup 403'd, resolve failed, and every PR silently fell back to manual merge across the fleet. The reusable now performs the lookup itself when pr-number is empty, using the App token it already mints (which carries pull-requests access).

Consumer migration

Repin to @82e55fa008d8b2f5254ba3a2624c22b78036eeb5 # v1.16.0, delete the local resolve job, and pass only head-sha: ${{ github.event.workflow_run.head_sha }}. Backward compatible: a caller still passing pr-number is unaffected.

Also rolls up the accumulated main work since v1.15.0 (#73#77).

Commits
  • b9d6408 Merge pull request #80 from three-cubes/fix/auto-merge-pass-repo-flag
  • d40aa51 fix(auto-merge): pass -R to gh pr merge so auto-merge actually arms
  • 028d38a Merge pull request #79 from three-cubes/fix/auto-merge-skeleton-resolve-from-...
  • 8185fdd fix(skeleton): drop the auto-merge resolve job (v1.16.0 resolves from head-sha)
  • 523bb10 Merge pull request #78 from three-cubes/fix/auto-merge-repin-v1160
  • 02fd8c3 fix(auto-merge): repin to v1.16.0 + drop local resolve job
  • 82e55fa Merge pull request #77 from three-cubes/fix/auto-merge-resolve-pr-from-head-sha
  • e9bf1e9 fix(auto-merge): resolve PR from head-sha inside the reusable
  • 14d0ecb Merge pull request #76 from three-cubes/docs/reconcile-canonical-ruleset
  • 25fa0e1 docs(governance): reconcile canon to the live 4-profile org-ruleset model
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…n-quality-gate.yml

Bumps [three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml](https://github.com/three-cubes/tc-pipelines) from 1.15.0 to 1.16.1.
- [Release notes](https://github.com/three-cubes/tc-pipelines/releases)
- [Changelog](https://github.com/three-cubes/tc-pipelines/blob/main/CHANGELOG.md)
- [Commits](three-cubes/tc-pipelines@7169245...b9d6408)

---
updated-dependencies:
- dependency-name: three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml
  dependency-version: 1.16.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated, dependency, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from a team as a code owner July 26, 2026 17:02
@github-actions

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

.github/workflows/ci.yml

PackageVersionLicenseIssue Type
three-cubes/tc-pipelines/.github/workflows/python-quality-gate.ymlb9d6408868eec5be56dbe57581aa086a95095d46NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
actions/three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml b9d6408868eec5be56dbe57581aa086a95095d46 UnknownUnknown

Scanned Files

  • .github/workflows/ci.yml

@three-cubes-agent
three-cubes-agent Bot enabled auto-merge July 26, 2026 17:03

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 66354b0581

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread .github/workflows/ci.yml
# private-infra-patterns secret so the detector stays ENFORCED, not a
# silent no-op. Stage 1..5 (contracts / integration / e2e) are untouched.
uses: three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml@71692450a1f339685ea4d88ad707bc36e75f5ac6 # v1.15.0
uses: three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml@b9d6408868eec5be56dbe57581aa086a95095d46 # v1.16.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Re-author the commit as the canonical app

This commit records both its author and committer as Codex <codex@openai.com>, so any PR range containing it violates the repository’s canonical identity policy and will be rejected by the no-LLM-attribution gate. Recreate the commit under the three-cubes-agent GitHub App identity.

AGENTS.md reference: AGENTS.md:L7-L14

Useful? React with 👍 / 👎.

Comment thread .github/workflows/ci.yml
# private-infra-patterns secret so the detector stays ENFORCED, not a
# silent no-op. Stage 1..5 (contracts / integration / e2e) are untouched.
uses: three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml@71692450a1f339685ea4d88ad707bc36e75f5ac6 # v1.15.0
uses: three-cubes/tc-pipelines/.github/workflows/python-quality-gate.yml@b9d6408868eec5be56dbe57581aa086a95095d46 # v1.16.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Exercise the upgraded reusable workflow before merge

Because this commit changes only .github/workflows/ci.yml, the changes job's python filter remains false and the arch-fitness job is skipped by its if: needs.changes.outputs.python == 'true' condition, so the newly pinned reusable workflow never starts on this PR. An incompatible workflow_call input or secret contract can therefore merge green and break the next Python-triggered run; include a no-op change to a path watched by the python filter so this caller is exercised before merge.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant