Skip to content

Bump gojiplus/py-canon/.github/workflows/reusable-ci.yml from 6381ef50660166e3836a2e687f81b5f9b5640b2e to 5171a442a11b1e45820b092b09af9af37efc5f9d - #9

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/gojiplus/py-canon/dot-github/workflows/reusable-ci.yml-5171a442a11b1e45820b092b09af9af37efc5f9d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/gojiplus/py-canon/dot-github/workflows/reusable-ci.yml-5171a442a11b1e45820b092b09af9af37efc5f9d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps gojiplus/py-canon/.github/workflows/reusable-ci.yml from 6381ef50660166e3836a2e687f81b5f9b5640b2e to 5171a442a11b1e45820b092b09af9af37efc5f9d.

Changelog

Sourced from gojiplus/py-canon/.github/workflows/reusable-ci.yml's changelog.

Changelog

All notable changes to this project are documented here.

The format follows Keep a Changelog. Release tags match the version committed in pyproject.toml; the fleet-facing v1 tag is a moving pointer advanced by the promote workflow after green CI, not a release of its own.

[Unreleased]

Fixed

  • Pinned Preen 0.6.2 in reusable CI so a newly published conformance rule cannot change every caller's required checks without a reviewed py-canon update, and authenticated its GitHub link checks to avoid anonymous throttling failures.
  • Dependabot recovery reports failed and missing checks and merge conflicts even when auto-merge is already enabled. Each sweep writes a linked summary; authentication and unexpected API failures fail the job.
  • Retired the separate Dependabot backfill script; dispatch the shared recovery workflow to process existing PRs using the same policy as scheduled runs.

Added

  • A lock-regression job in the reusable CI fails a pull request whose uv.lock pins any package below the version on the base branch, naming each one. A feature branch merged with a stale lock silently downgrades everything Dependabot bumped since the branch was cut, and Dependabot then re-raises every one of those bumps: appeler/pranaam#48 took twelve packages back two weeks and produced seven duplicate PRs. Label a PR lock-downgrade-ok when the downgrade is deliberate. The job is part of gate, so no ruleset change is needed.
  • The Dependabot template tracks transitive dependencies too (allow: dependency-type: all). The default only follows what pyproject.toml names, so lock-only pins sat untouched until something upstream complained: gojiplus/reporoulette carried grpcio 1.76 for eleven months until google-auth 2.57 began warning at import that 1.83 is the floor, which with warnings-as-errors failed every test module at collection. tools/fleet_dependabot_allow.py inserts the block into each fleet repo's existing config without overwriting per-repo groups.
  • tools/fleet_align_rulesets.py brings every fleet repo's default-branch ruleset and merge settings to the shape STANDARD.md describes: admin bypass on the ruleset, auto-merge and delete-branch-on-merge on, and the standard ruleset created where a canon-CI repo had none. A survey on 2026-09-08 found 21 of 47 repos drifted, mostly the August finite-sample adoptions, which is why the Dependabot sweep had to merge outright there instead of arming, and why a fleet file push was refused on 17 of them. Required checks are left to set-required-checks.sh.
  • tools/fleet_python_floor.py raises a fleet repo's requires-python to

... (truncated)

Commits
  • 5171a44 Pin Preen in reusable CI (#93)
  • 30ba4ea Bump the python-minor-and-patch group with 2 updates (#91)
  • 1242b63 Bump astral-sh/setup-uv in the actions-minor-and-patch group (#90)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [gojiplus/py-canon/.github/workflows/reusable-ci.yml](https://github.com/gojiplus/py-canon) from 6381ef50660166e3836a2e687f81b5f9b5640b2e to 5171a442a11b1e45820b092b09af9af37efc5f9d.
- [Release notes](https://github.com/gojiplus/py-canon/releases)
- [Changelog](https://github.com/gojiplus/py-canon/blob/main/CHANGELOG.md)
- [Commits](gojiplus/py-canon@6381ef5...5171a44)

---
updated-dependencies:
- dependency-name: gojiplus/py-canon/.github/workflows/reusable-ci.yml
  dependency-version: 5171a442a11b1e45820b092b09af9af37efc5f9d
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants