SRE-891, SRE-904: Pass the Renovate cipher key and fix the todo-comments trigger - #155
Draft
TimDiekmann wants to merge 2 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
hashintel/.github#99 split the centralized Renovate workflow into a mint job and a run job; the installation token crosses the job boundary encrypted with
RENOVATE_TOKEN_ENC_KEY. This wires the caller up to that contract, mirroring hashintel/hash#9192, and re-enables the todo-comments scan on PRs.Related links
What does this change?
housekeeping.yml: bump thehashintel/.githubpin tob7a5d7fand passRENOVATE_TOKEN_ENC_KEYthrough to the reusable workflow (the secret is already set on this repo)preflight.yml: move the todo-comments job into a dedicatedpreflight-todo-comments.ymltriggered onpull_request(matching hash and brunch). The reusable scan job ispull_request-only since SRE-891, so it was silently skipped when called underpull_request_target. The check name staysTodo comments / Scan.hashintel/.githubpins bumped to the same SHAHow to test this?
Todo comments / Scancheck on this PR should now report success/failure instead of skipped