ci(deps): Bump the actions group with 3 updates - #446
Conversation
Bumps the actions group with 3 updates: [mamba-org/setup-micromamba](https://github.com/mamba-org/setup-micromamba), [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action). Updates `mamba-org/setup-micromamba` from 3.1.0 to 3.2.1 - [Release notes](https://github.com/mamba-org/setup-micromamba/releases) - [Commits](mamba-org/setup-micromamba@ce51e99...f457c30) Updates `actions/attest-build-provenance` from 4.1.1 to 4.2.2 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@0f67c3f...4d10147) Updates `github/codeql-action/upload-sarif` from 4.37.4 to 4.37.6 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@f205ea1...5595cca) --- updated-dependencies: - dependency-name: mamba-org/setup-micromamba dependency-version: 3.2.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/attest-build-provenance dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
Review lane — Codex leg
The one finding, and its disposition
It is answered rather than deferred: the composite action's bump is #445, opened by the same What is deferred is the missing guard, which outlives this pair and would let the same split |
|
@coderabbitai full review Final head The unmetered leg is done and recorded above: Codex read this diff first and raised one Three pins move here and all three were verified against their upstream repositories rather than |
|
🧠 Learnings used
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThe pull request updates pinned GitHub Actions versions in the packaging, release, and scorecard workflows. ChangesWorkflow action updates
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Lane state: throttled, waiting — that ask reviewed nothingThe full-review request above was refused: "Review limit reached … Next review available in: 29 Recording it explicitly, because two things follow from it and both matter:
The ask was mine, made about 30 minutes after the one on #445 rather than the roughly 43 the seat's Nothing about the diff has changed and nothing needs to: Codex has read it, its one |
|
@coderabbitai full review Retrying at the time the limit named: the refusal above was posted 02:49:05Z with "Next review available in: 29 minutes", and it is now past 03:19Z. That earlier ask produced no review, so it is not one of the two completed reviews and the cap on this PR is still untouched. Final head is unchanged at |
|
Your plan includes PR reviews subject to rate limits. Reviews are available now. |
Still throttled — second refusal, and the signals disagree with each otherThe retry at 03:19:54Z landed after the time the first refusal named (02:49:05Z + 29 minutes =
So the green status check is, again, not evidence of a review: it is green while its own description The interval the refusal names is a floor, not a guarantee. The limit is a rolling window that Nothing about the diff has changed and nothing needs to. Codex has read it, its one |
|
@coderabbitai full review Third ask, spaced deliberately rather than retried on the clock: the last one was 03:19:54Z and this is 04:10Z, ~51 minutes on, against a stated interval of 29 minutes that turned out to be a floor rather than a guarantee. Neither previous ask produced a review, so the two-completed-reviews cap on this PR is still at zero. Nothing has changed on the diff and nothing needs to. Final head remains Three |
|
🧠 Learnings used✅ Action performedFull review finished. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/packaging.yml:
- Line 77: Update the setup-micromamba action reference in
.github/actions/setup-env/action.yml at line 40 to pin commit
f457c30a868e4760d3a6fcea5f25dc655b8edf39 (v3.2.1), matching the existing pins in
.github/workflows/packaging.yml at line 77 and .github/workflows/release.yml at
line 143; no changes are needed at those workflow sites.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro Plus
Run ID: ac7b478f-4da2-48cf-82c8-5397a79127fc
📒 Files selected for processing (3)
.github/workflows/packaging.yml.github/workflows/release.yml.github/workflows/scorecard.yml
Lane state — one completed metered review, one finding, disposedReview 1 of the permitted two completed at
Disposition: satisfied at the head being merged, and the finding is inverted by the base it read. Worth naming as a recurring hazard rather than a one-off: a provider reviewing at the merge base will Next: the second permitted review. The cap is two completed reviews and this was one, so a second Timing is the constraint, not permission. This seat has refused twice tonight at 30 and 51 minutes, |
|
@coderabbitai full review Second of the two permitted reviews, asked now that the first one's finding is disposed of — replied to with evidence and its thread resolved — which is the ordering the lane requires. Disposal on the record moves no head, so the final head is unchanged at On the finding itself, since it is the one thing worth re-checking: it asked for All required checks green at that head. Codex read it earlier and raised one P2, answered the same way. |
|
I used the repository review-governance context on completed-review counting. 🧠 Learnings used
|
Third refusal — acked, then rate limited, no reviewThe 05:02:02Z ask was acknowledged at 05:02:18Z with "I will perform the second full review at Tally on this PR, since only one of these counts against anything:
One completed review stands. One remains available, since a request that produced no review is not one of the two. The cap is not spent, so the Codex close is not open to this PR and is not being reached for — what this needs is the second metered review, which is a wait rather than a blocker. Spacing the next ask well past an hour rather than on any interval the seat quotes: tonight's stated 29 minutes proved to be a floor, and the pattern of ack-then-limit is the documented approach to an adaptive limit that suppresses reviews for hours. Nothing about the diff has changed; final head remains |
|
@coderabbitai full review Asking again at 06:21Z, 79 minutes after the last attempt and 128 after the one completed review, having deliberately skipped the intervals the earlier refusals named — both proved to be floors rather than guarantees. Still the second of the two permitted reviews, and still in order: the first review's single 🟠 Major has been answered with evidence and its thread resolved, and disposal on the record moves no head, so the final head is unchanged at Standing correction on that finding, since it is the only thing in the diff worth a second look: it asked for All required checks green at that head; |
|
🧠 Learnings used✅ Action performedFull review finished. |
Gate closed — merging
Threads: 0 unresolved. Checks: green, |
Bumps the actions group with 3 updates: mamba-org/setup-micromamba, actions/attest-build-provenance and github/codeql-action/upload-sarif.
Updates
mamba-org/setup-micromambafrom 3.1.0 to 3.2.1Release notes
Sourced from mamba-org/setup-micromamba's releases.
Commits
f457c30fix: Extract prerelease packages on Windows with --force-local (#315)d6abac3feat: Support prereleases of micromamba (#310)Updates
actions/attest-build-provenancefrom 4.1.1 to 4.2.2Release notes
Sourced from actions/attest-build-provenance's releases.
Commits
4d10147Bump actions/attest from 4.2.0 to 4.2.1 in the actions-minor group (#862)e3fe62eBump the actions-minor group with 2 updates (#860)Updates
github/codeql-action/upload-sariffrom 4.37.4 to 4.37.6Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
5595ccaMerge pull request #4071 from github/update-v4.37.6-6a9359a1bec9c757Add change note for PR 407045c8742Update changelog for v4.37.66a9359aMerge pull request #4070 from github/mbg/remote-address/change-file-default065cdc0ChangeDEFAULT_CONFIG_FILE_NAMEf99dd5aMerge pull request #4066 from github/dependabot/npm_and_yarn/js-yaml-5.2.21804b21Merge pull request #4068 from github/mergeback/v4.37.5-to-main-d1ba80a13020a2fRebuild93c3a5aUpdate changelog and version after v4.37.5d1ba80aMerge pull request #4067 from github/update-v4.37.5-1cd4d01d5Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsSummary by CodeRabbit