Skip to content

chore(deps): bump acgetchell/research-repo-tools/.github/workflows/dependabot-approve.yml from cbb2ea6dee8866b3f0547bca935aef48fdd71707 to b972cbfd717319abaa68d9b1373711ad6f163294 in the github-actions group - #270

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-bf3f53314a
Oct 5, 2026

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 1 update: acgetchell/research-repo-tools/.github/workflows/dependabot-approve.yml.

Updates acgetchell/research-repo-tools/.github/workflows/dependabot-approve.yml from cbb2ea6dee8866b3f0547bca935aef48fdd71707 to b972cbfd717319abaa68d9b1373711ad6f163294

Changelog

Sourced from acgetchell/research-repo-tools/.github/workflows/dependabot-approve.yml's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[0.1.7] - 2026-09-26

Merged Pull Requests

  • Bump hatchling in the python group #53
  • Bump the github-actions group with 4 updates #52

Added

  • Add reusable patch approval and auto-merge 2ef9ba8

    • Approve allowlisted uv and Cargo patch updates using repository-owned dependency and file policies, including every member of grouped updates.
    • Bind approval to a single GitHub-signed Dependabot head commit and require active rulesets with stale-review dismissal and strict checks.
    • Replace CodeRabbit approval polling and the personal token requirement with GITHUB_TOKEN and native squash auto-merge.
    • Provide settings payloads and document consumer SHA pinning, setup, rollout, and post-merge verification.
  • Add shared Python adoption, security scans, and cleanup d975bb2

    • Add opt-in Python baseline inheritance and recoverable preview/apply migration while preserving consumer runtime and lint policies.
    • Manage cargo-deny and checksum-verified OSV/Gitleaks binaries, with explicit scan inputs, redacted reports, and blocking failure handling.
    • Share Semgrep inventory, Rust documentation scans, and fixture checks.
    • Support first-release preparation without a fabricated predecessor and opt-in blocking of dependency installation in notebooks.
    • Add just clean for obsolete package-owned installations, with previews and retention roots; keep user-wide installations untouched.
    • Preserve executable helpers and reject linked adoption environments; handle relative cleanup roots and TOML tables without final newlines.
    • Correct Windows Bash CRLF assumptions in the Dependabot test harness.
    • Document public configuration factories and consumer migration, cleanup, and release contracts; repair README links for PyPI.
    • Update platformdirs to 4.11.15.

Fixed

  • Make Dependabot workflow tests portable 3f1bfc9

    • Use jq's portable -b option for Ubuntu compatibility while preserving LF output on Windows.
    • Pass Bash scripts through binary stdin to preserve embedded quoting and prevent Windows newline translation.
    • Add a dynamic PyPI version badge to the README linking to the package.
  • Isolate Dependabot test scripts from child stdin 937f151

    • Run Bash from temporary files with LF line endings so child processes cannot consume the workflow script through stdin.
    • Normalize jq output before simulating Windows CRLF behavior.
    • Document that GITHUB_TOKEN approval replaces CodeRabbit polling and personal tokens while required CodeRabbit status checks still apply.
  • Preserve exact CRLF bytes in Dependabot test fixtures a5aa0f5

... (truncated)

Commits
  • b972cbf build(deps-dev): bump hatchling (#68)
  • 58649a8 build(deps): bump the github-actions group with 4 updates (#67)
  • 0a02204 Merge pull request #55 from acgetchell/release/v0.1.7
  • 8c05f83 chore(release): release v0.1.7
  • d2469f6 build(deps): bump the github-actions group with 4 updates (#52)
  • 6a5b1b8 Merge pull request #54 from acgetchell/fix/dependabot-auto-merge
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…pendabot-approve.yml

Bumps the github-actions group with 1 update: [acgetchell/research-repo-tools/.github/workflows/dependabot-approve.yml](https://github.com/acgetchell/research-repo-tools).


Updates `acgetchell/research-repo-tools/.github/workflows/dependabot-approve.yml` from cbb2ea6dee8866b3f0547bca935aef48fdd71707 to b972cbfd717319abaa68d9b1373711ad6f163294
- [Release notes](https://github.com/acgetchell/research-repo-tools/releases)
- [Changelog](https://github.com/acgetchell/research-repo-tools/blob/main/CHANGELOG.md)
- [Commits](acgetchell/research-repo-tools@cbb2ea6...b972cbf)

---
updated-dependencies:
- dependency-name: acgetchell/research-repo-tools/.github/workflows/dependabot-approve.yml
  dependency-version: b972cbfd717319abaa68d9b1373711ad6f163294
  dependency-type: direct:production
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github-actions labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from acgetchell as a code owner October 5, 2026 10:08
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github-actions labels Oct 5, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by the Dependabot policy. Required checks and review threads still gate merging.

@github-actions
github-actions Bot enabled auto-merge (squash) October 5, 2026 10:08
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: acgetchell/la-stack/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 07d86ab5-b19a-48cb-948f-f658f934e71d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot merged commit 1615b1b into main Oct 5, 2026
15 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-bf3f53314a branch October 5, 2026 10:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github-actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants