Skip to content

Commit 35349e5

Browse files
authored
Merge branch 'main' into dependabot/gradle/main/com.fasterxml.jackson.core-jackson-databind-2.22.2
2 parents c0fdeac + dbca9e0 commit 35349e5

5 files changed

Lines changed: 30 additions & 27 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929
# Everything the jars are built with. Gradle provisions no JDKs of its own —
3030
# auto-download is off in gradle.properties — so JDK21_HOME is the toolchain it reads.
3131
- name: Install JDK 21
32-
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
32+
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
3333
with:
3434
distribution: temurin
3535
java-version: '21'
@@ -97,7 +97,7 @@ jobs:
9797
# After GraalVM, so JAVA_HOME — and the Gradle daemon — is 21 like everywhere else, and
9898
# so the jars this job feeds into native-image are compiled at 21. GRAALVM_HOME survives.
9999
- name: Install JDK 21 for the jars
100-
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
100+
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
101101
with:
102102
distribution: temurin
103103
java-version: '21'

‎.github/workflows/codeql-analysis.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,15 +27,15 @@ jobs:
2727
# are provisioned by gradle-jdks (gradle/jdks/**), because gradle.properties
2828
# disables installation auto-detection.
2929
- name: Set up a bootstrap JDK
30-
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
30+
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
3131
with:
3232
distribution: temurin
3333
java-version: '21'
3434

3535
# Initializes the CodeQL tools for scanning.
3636
# Must run AFTER setup-java so CodeQL hooks into the correct JDK.
3737
- name: Initialize CodeQL
38-
uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
38+
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4
3939
with:
4040
languages: 'java'
4141

@@ -45,4 +45,4 @@ jobs:
4545
run: ./gradlew --no-build-cache clean compileJava compileTestJava
4646

4747
- name: Perform CodeQL Analysis
48-
uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
48+
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4

‎.github/workflows/dependabot-automerge.yml‎

Lines changed: 1 addition & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -17,25 +17,14 @@ jobs:
1717
with:
1818
github-token: "${{ secrets.GITHUB_TOKEN }}"
1919

20-
# GITHUB_TOKEN, deliberately: a review starts no workflow run and does not need to, so the
21-
# short-lived token is enough and the approval shows in the PR as the bot rather than as a
22-
# person. This needs `can_approve_pull_request_reviews` on the repository — no `permissions`
23-
# block can stand in for it, and without it GitHub refuses with "GitHub Actions is not
24-
# permitted to approve pull requests".
2520
- name: Approve patch and minor updates
2621
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
2722
run: gh pr review --approve "$PR_URL"
2823
env:
2924
PR_URL: ${{ github.event.pull_request.html_url }}
3025
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
3126

32-
# BOT_PAT here, and not GITHUB_TOKEN: auto-merge is completed on behalf of whoever enabled
33-
# it, and a push made by GITHUB_TOKEN starts no workflow runs. Enabled with GITHUB_TOKEN the
34-
# merge lands on main silently — no CI, no CodeQL, no dependency snapshot, and
35-
# update-pr-branch never wakes to rebase the remaining PRs, so the automation cuts its own
36-
# legs. A PAT is a real user, so the push behaves like any other.
37-
- name: Enable auto-merge for patch and minor updates
38-
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
27+
- name: Enable auto-merge for all PRs
3928
run: gh pr merge --auto --squash "$PR_URL"
4029
env:
4130
PR_URL: ${{ github.event.pull_request.html_url }}

‎.github/workflows/dependency-submission.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
1515

1616
- name: Set up a bootstrap JDK
17-
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
17+
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
1818
with:
1919
distribution: temurin
2020
java-version: '21'

‎mise.toml‎

Lines changed: 23 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -25,17 +25,29 @@ run = "act push --job native --matrix platform:linux-aarch64"
2525
# (authenticated with admin on this repository) and the 1Password CLI (`op signin` first).
2626

2727
[tasks."gh:secrets"]
28-
description = "Set the repository's Actions secrets from 1Password (op)"
28+
description = "Set the repository's Actions and Dependabot secrets from 1Password (op)"
2929
shell = "bash -c"
3030
quiet = true # suppress mise's `[task] $ <first line>` command echo
3131
env = { NO_COLOR = "1" } # suppress gh's OSC-11 terminal-background probe
32-
run = '''
32+
run = """
3333
set -euo pipefail
3434
35-
# BOT_PAT is consumed by .github/workflows/update-pr-branch.yml, and it cannot be GITHUB_TOKEN:
36-
# a push made with GITHUB_TOKEN does not start workflow runs, so a PR branch would be brought
37-
# up to date and then never re-checked — which is the whole point of that workflow. A
38-
# fine-grained PAT scoped to this repository with Contents: read and write is enough.
35+
# BOT_PAT is consumed by update-pr-branch.yml and by the auto-merge step of
36+
# dependabot-automerge.yml, and it cannot be GITHUB_TOKEN: a push made with GITHUB_TOKEN starts no
37+
# workflow runs, so a branch would be brought up to date — or a pull request merged — and then
38+
# never re-checked.
39+
#
40+
# The token needs these repository permissions:
41+
# Pull requests Write PUT /repos/{owner}/{repo}/pulls/{n}/update-branch requires it
42+
# Contents Write pushing the updated branch and the merge commit
43+
#
44+
# It is written to BOTH secret stores. A run triggered by a Dependabot event cannot read Actions
45+
# secrets at all — it reads the Dependabot store instead — so a token present only in Actions
46+
# expands to an empty string there, and gh fails with "set the GH_TOKEN environment variable".
47+
#
48+
# --repo, because this checkout has two remotes (origin and upstream) and gh refuses to guess.
49+
repo="$(git remote get-url origin | sed -E 's#(git@github\\.com:|https://github\\.com/)##; s#\\.git$##')"
50+
3951
apply() {
4052
local name="$1" ref="$2" value
4153
if [[ "$ref" == *TODO* ]]; then
@@ -46,9 +58,11 @@ apply() {
4658
echo " Create that item in 1Password (or point the reference at an existing one), then re-run." >&2
4759
return 1
4860
fi
49-
gh secret set "$name" --body "$value"
50-
echo "✓ $name set"
61+
for store in actions dependabot; do
62+
gh secret set "$name" --app "$store" --repo "$repo" --body "$value"
63+
echo "✓ $name set ($store)"
64+
done
5165
}
5266
5367
apply BOT_PAT 'op://Private/open-java-format/GitHub/bot-pat'
54-
'''
68+
"""

0 commit comments

Comments
 (0)