Rebuild comment sync as a post-merge repair caller - #54
Conversation
Replaces the in-PR workflow_run caller: any non-Dependabot push to a Dependabot branch flips the retriggered runs' actor off dependabot[bot], lifting the Dependabot sandbox for the PR's unreviewed action bumps (verified live on basecamp-cli#566; see basecamp/.github#11). The reusable workflow now runs post-merge: on workflow-file pushes to the default branch it repairs drifted comments via a comment-only auto-merging PR — only reviewed code ever executes. Dependabot itself maintains the bare comments on its own PRs after the bare-pin restructure. Lands disabled; enabled per repo after a full-cycle exercise.
Sensitive Change Detection (shadow mode)This PR modifies control-plane files:
|
There was a problem hiding this comment.
Pull request overview
This PR updates the repo’s Dependabot action-pin comment sync workflow to the post-merge “repair PR” model, delegating all logic to the SHA-pinned reusable workflow in basecamp/.github and avoiding any pushes to Dependabot branches (preserving the Dependabot sandbox behavior).
Changes:
- Replace the in-PR
workflow_runtrigger with a post-mergepushtrigger onmainscoped to workflow-file changes. - Update the reusable workflow pin to
45d3fc9588f15d50fbccde7476418007dd19e16eand adjust permissions for the new repair-PR model. - Simplify the caller inputs by removing dispatch inputs and relying on the reusable workflow’s post-merge reconciliation behavior.
Tip
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.
Comments suppressed due to low confidence (1)
.github/workflows/dependabot-sync-actions-comments.yml:28
actions: writeis a high-privilege permission and is unique among this repo’s workflows. Add a brief inline rationale (e.g., needed for approving held workflow runs on the repair PR) to make the security intent clear during audits/reviews.
contents: read
actions: write
pull-requests: write
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Replaces the in-PR
workflow_runcaller with the post-merge model (basecamp/.github#11, pinned 45d3fc95): any non-Dependabot push to a Dependabot branch flips the retriggered runs' actor offdependabot[bot], lifting the Dependabot sandbox for the PR's unreviewed action bumps — verified live on basecamp/basecamp-cli#566. Post-merge, the reusable workflow repairs drifted comments via a comment-only auto-merging PR; every pin it touches is already reviewed, and nothing is ever pushed to a Dependabot branch. Dependabot maintains the bare comments on its own PRs after the bare-pin restructure (Layer 1, merged fleet-wide).The workflow entry stays disabled through this merge; repos are enabled one at a time after a full-cycle exercise (seeded drift → repair PR → held-run approval → CI → auto-merge → terminal no-op) in one repo.