Skip to content

Bump gojiplus/py-canon/.github/workflows/reusable-ci.yml from 07c6621880b82afd28ab7230eab6e79f96d080e3 to a227c2058f0c3559b05edb0118e5cfff28de718b - #5

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/gojiplus/py-canon/dot-github/workflows/reusable-ci.yml-a227c2058f0c3559b05edb0118e5cfff28de718b
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/gojiplus/py-canon/dot-github/workflows/reusable-ci.yml-a227c2058f0c3559b05edb0118e5cfff28de718b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps gojiplus/py-canon/.github/workflows/reusable-ci.yml from 07c6621880b82afd28ab7230eab6e79f96d080e3 to a227c2058f0c3559b05edb0118e5cfff28de718b.

Changelog

Sourced from gojiplus/py-canon/.github/workflows/reusable-ci.yml's changelog.

Changelog

All notable changes to this project are documented here.

The format follows Keep a Changelog. Release tags match the version committed in pyproject.toml; the fleet-facing v1 tag is a moving pointer advanced by the promote workflow after green CI, not a release of its own.

[Unreleased]

Added

  • A lock-regression job in the reusable CI fails a pull request whose uv.lock pins any package below the version on the base branch, naming each one. A feature branch merged with a stale lock silently downgrades everything Dependabot bumped since the branch was cut, and Dependabot then re-raises every one of those bumps: appeler/pranaam#48 took twelve packages back two weeks and produced seven duplicate PRs. Label a PR lock-downgrade-ok when the downgrade is deliberate. The job is part of gate, so no ruleset change is needed.
  • The Dependabot template tracks transitive dependencies too (allow: dependency-type: all). The default only follows what pyproject.toml names, so lock-only pins sat untouched until something upstream complained: gojiplus/reporoulette carried grpcio 1.76 for eleven months until google-auth 2.57 began warning at import that 1.83 is the floor, which with warnings-as-errors failed every test module at collection. tools/fleet_dependabot_allow.py inserts the block into each fleet repo's existing config without overwriting per-repo groups.
  • tools/fleet_align_rulesets.py brings every fleet repo's default-branch ruleset and merge settings to the shape STANDARD.md describes: admin bypass on the ruleset, auto-merge and delete-branch-on-merge on, and the standard ruleset created where a canon-CI repo had none. A survey on 2026-09-08 found 21 of 47 repos drifted, mostly the August finite-sample adoptions, which is why the Dependabot sweep had to merge outright there instead of arming, and why a fleet file push was refused on 17 of them. Required checks are left to set-required-checks.sh.
  • tools/fleet_python_floor.py raises a fleet repo's requires-python to the 3.12 floor STANDARD.md declares, editing every place the old floor is pinned (ruff target, classifier, pyright, CI matrix), relocking, and opening an auto-merging PR so CI decides. 24 of 47 repos still said >=3.11 on 2026-09-08; gojiplus/gringotts's lower-bounds job could not resolve py-canon 1.3.0 (itself >=3.12) under that floor.
  • Reusable CI callers can set test-timeout-minutes and wheel-timeout-minutes when a complete test suite legitimately exceeds the default 30- and 20-minute job budgets. The defaults remain unchanged.

[1.3.0] - 2026-08-26

Fixed

... (truncated)

Commits
  • a227c20 Treat a disabled ruleset as drift (#84)
  • 47846b0 Bump the python-minor-and-patch group with 6 updates (#83)
  • e67aaa7 Add the tool that raises a fleet repo's Python floor to 3.12 (#81)
  • f698faa Align fleet rulesets and merge settings with the standard (#80)
  • a2ce6cb Bump actions/deploy-pages in the actions-minor-and-patch group (#82)
  • bf3b232 Track transitive dependencies in Dependabot, template and fleet (#79)
  • f369a27 Fail a PR whose uv.lock pins anything below the base branch (#78)
  • 4a2ac67 Bump ruff from 0.16.3 to 0.16.5 in the python-minor-and-patch group (#76)
  • b17ef8a Meet the Python floor this repo publishes
  • d589aca Bump ruff from 0.16.3 to 0.16.4 in the python-minor-and-patch group (#74)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [gojiplus/py-canon/.github/workflows/reusable-ci.yml](https://github.com/gojiplus/py-canon) from 07c6621880b82afd28ab7230eab6e79f96d080e3 to a227c2058f0c3559b05edb0118e5cfff28de718b.
- [Release notes](https://github.com/gojiplus/py-canon/releases)
- [Changelog](https://github.com/gojiplus/py-canon/blob/main/CHANGELOG.md)
- [Commits](gojiplus/py-canon@07c6621...a227c20)

---
updated-dependencies:
- dependency-name: gojiplus/py-canon/.github/workflows/reusable-ci.yml
  dependency-version: a227c2058f0c3559b05edb0118e5cfff28de718b
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/gojiplus/py-canon/dot-github/workflows/reusable-ci.yml-a227c2058f0c3559b05edb0118e5cfff28de718b branch September 21, 2026 00:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant