chore(deps): update ferrlabs/.github digest to 539e9ac - #363
Conversation
There was a problem hiding this comment.
Digest bump for FerrLabs/.github (15286b3 → fba6f4b), pinning six reusable workflow calls in docker.yml, release.yml, renovate-rebase.yml, security-scan.yml, sonarqube.yml.
Only one commit sits between the two digests (#334, "let a caller disambiguate the concurrency group per call"). It adds a new concurrency-key input to reusable-ci-node.yml and reusable-sonarqube-scan.yml, folded into the workflow-level concurrency.group string. It's optional with default: '', and LFSX's sonarqube.yml doesn't set it, so the group key is unchanged for this repo — no behavior change here. LFSX doesn't call reusable-ci-node.yml at all.
CI checks visible so far are green or still running, nothing failed.
Uneventful bump, safe to merge.
SonarQube — aucune nouvelle issueComparaison entre le projet bac à sable de cette PR et la branche par défaut : SonarQube Community n'analyse pas les PR, ce delta est calculé côté CI. Détail |
0bded3a to
483eb35
Compare
| contents: write | ||
| id-token: write | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ferrflow-release.yml@15286b37e14c898251a98ea18d21b69ab0bf777f # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ferrflow-release.yml@539e9aca37e08abde8d9cefbe13cd98fa62b1b41 # main |
| jobs: | ||
| dispatch: | ||
| uses: FerrLabs/.github/.github/workflows/reusable-renovate-dispatch.yml@15286b37e14c898251a98ea18d21b69ab0bf777f # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-renovate-dispatch.yml@539e9aca37e08abde8d9cefbe13cd98fa62b1b41 # main |
| contents: read | ||
| security-events: write | ||
| uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@15286b37e14c898251a98ea18d21b69ab0bf777f # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@539e9aca37e08abde8d9cefbe13cd98fa62b1b41 # main |
| contents: read | ||
| pull-requests: write | ||
| uses: FerrLabs/.github/.github/workflows/reusable-sonarqube-scan.yml@15286b37e14c898251a98ea18d21b69ab0bf777f # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-sonarqube-scan.yml@539e9aca37e08abde8d9cefbe13cd98fa62b1b41 # main |
There was a problem hiding this comment.
Follow-up: since my last review the PR advanced past fba6f4b to a new digest (539e9ac). The only additional upstream commit is FerrLabs/.github#331, which bumps the FerrFlow action used inside reusable-ferrflow-release.yml from v7.11.1 to v7.20.1.
Checked all 30 intervening FerrFlow releases (v7.11.2 → v7.20.1): all additive features (buildMetadata, new package-manager formats, PyPI trusted publishing, doc packaging) or bug fixes to monorepo/cascade/changelog logic, none marked breaking. The one entry that touches the area LFSX actually uses — v7.13.2 "postBump runs after changelog generation, not before" — is a schema/doc description fix only; the runtime order was already correct in v7.11.1, so LFSX's postBump: "cargo update -p lfsx-server -p lfsx" hook (.ferrflow) is unaffected.
CI is now green (SonarQube finished successfully; everything else success/skipped as expected). Uneventful, safe to merge.
This PR contains the following updates:
15286b3→539e9acWarning
Some dependencies could not be looked up. Check the warning logs for more information.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.