Skip to content

chore(deps): update stranske/workflows digest to c2537cc - #757

Merged
stranske merged 1 commit into
mainfrom
renovate/stranske-workflows-digest
Jun 22, 2026
Merged

chore(deps): update stranske/workflows digest to c2537cc#757
stranske merged 1 commit into
mainfrom
renovate/stranske-workflows-digest

Conversation

@renovate

@renovate renovate Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
stranske/Workflows (changelog) action digest d68de19c2537cc

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from stranske as a code owner June 19, 2026 17:55
@renovate
renovate Bot temporarily deployed to agent-standard June 19, 2026 17:55 Inactive
@renovate
renovate Bot temporarily deployed to agent-standard June 19, 2026 17:55 Inactive
@coderabbitai

coderabbitai Bot commented Jun 19, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The pinned SHA for stranske/Workflows/.github/actions/setup-api-client is updated in two "Workflows fallback" steps within .github/workflows/agents-guard.yml: one in the pull_request_target path (line 114) and one in the pull_request path (line 183).

Changes

SHA Bump for Workflows Fallback Action

Layer / File(s) Summary
Update pinned SHA in both fallback steps
.github/workflows/agents-guard.yml
Both Setup API client (Workflows fallback) steps — for pull_request_target and pull_request flows — are updated to the same new pinned SHA for stranske/Workflows/.github/actions/setup-api-client.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Suggested reviewers

  • stranske
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: updating a dependency digest for stranske/workflows from one SHA to another.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/stranske-workflows-digest

Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate
renovate Bot had a problem deploying to agent-standard June 19, 2026 17:55 Failure
@renovate
renovate Bot temporarily deployed to agent-standard June 19, 2026 17:55 Inactive
@stranske-keepalive

Copy link
Copy Markdown
Contributor

Workflow source needed

PR #757 needs either a linked GitHub issue or one valid non-issue Workflow Source before PR metadata automation can manage it safely.

Please do one of:

  • Add <!-- meta:issue:123 --> or a normal Closes #123 / Related to #123 line.
  • Check one Workflow Source option in the PR body.
  • Add a hidden marker such as <!-- workflow-source:local_request -->, <!-- workflow-source:manual_remote -->, <!-- workflow-source:review_followup -->, <!-- workflow-source:sync_campaign -->, or <!-- workflow-source:dependabot -->.
  • Add a workflow source label such as workflow:source-direct-pr, workflow:source-local-request, workflow:source-review-followup, workflow:source-sync, or workflow:no-automation.

Once a valid source is present, this warning will not be reposted.

@github-actions

github-actions Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Agents Gate Followups. Do not edit.

@github-actions

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Keepalive Loop Reporter. Do not edit.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/agents-guard.yml (1)

109-117: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Synced file should be updated upstream first.

Per coding guidelines, agents-*.yml files are synced from stranske/Workflows and should not be edited locally. This dependency bump should be applied in stranske/Workflows first to avoid sync conflicts.

The SHA update itself is technically valid—the linked repository research confirms backward compatibility with no breaking changes between the two commits.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/agents-guard.yml around lines 109 - 117, The
agents-guard.yml file is a synced file from the upstream stranske/Workflows
repository and should not be edited locally. Revert the SHA update to the
setup-api-client action (the hash c2537cc959f2ce05926c4639d25b90678abc97bc) from
this file to its previous value. Instead, apply this same SHA update in the
upstream stranske/Workflows repository first, then sync the changes back to this
repository to avoid sync conflicts in the future.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/agents-guard.yml:
- Around line 109-117: The agents-guard.yml file is a synced file from the
upstream stranske/Workflows repository and should not be edited locally. Revert
the SHA update to the setup-api-client action (the hash
c2537cc959f2ce05926c4639d25b90678abc97bc) from this file to its previous value.
Instead, apply this same SHA update in the upstream stranske/Workflows
repository first, then sync the changes back to this repository to avoid sync
conflicts in the future.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: be5ddbfb-5590-4650-922a-fbded2c4080e

📥 Commits

Reviewing files that changed from the base of the PR and between d4e34d2 and 290f063.

📒 Files selected for processing (1)
  • .github/workflows/agents-guard.yml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • stranske/Workflows (auto-detected)
📜 Review details
🧰 Additional context used
📓 Path-based instructions (5)
.github/workflows/**/*.yml

📄 CodeRabbit inference engine (.github/copilot-instructions.md)

.github/workflows/**/*.yml: Do not add top-level permissions: block on workflow_call reusable workflows - this conflicts with caller permissions
Avoid invalid YAML syntax, invalid permission scopes, and circular workflow references when creating GitHub Actions workflows

Files:

  • .github/workflows/agents-guard.yml
**/.github/workflows/*.yml

📄 CodeRabbit inference engine (CLAUDE.md)

First-party consumers should reference reusable workflows with @main. Only pin to an exact commit SHA for a controlled, documented reason.

Files:

  • .github/workflows/agents-guard.yml
{.github/workflows/agents-*.yml,.github/workflows/autofix.yml,.github/codex/**}

📄 CodeRabbit inference engine (CLAUDE.md)

Synced workflows (e.g., agents-*.yml, autofix.yml), prompts in .github/codex/, and synced scripts/docs should not be edited locally. Fix them in stranske/Workflows instead, which manages them through .github/sync-manifest.yml.

Files:

  • .github/workflows/agents-guard.yml
.github/workflows/**/*.{yml,yaml}

📄 CodeRabbit inference engine (AGENTS.md)

.github/workflows/**/*.{yml,yaml}: When editing workflow infrastructure, verify if the work belongs in stranske/Workflows instead. The answer is usually yes if the change affects reusable workflows, agent prompts or routing, keepalive/autofix/verifier behavior, synced workflow files, or synced scripts or docs.
First-party consumers should reference reusable workflows with @main by default. Only pin to an exact commit SHA if intentionally controlling for a specific reason.

Files:

  • .github/workflows/agents-guard.yml
.github/workflows/agents-*.{yml,yaml}

📄 CodeRabbit inference engine (AGENTS.md)

Synced workflow files including agents-*.yml, autofix.yml, prompts in .github/codex/, and synced scripts/docs should be fixed in stranske/Workflows first, not edited locally.

Files:

  • .github/workflows/agents-guard.yml
🔀 Multi-repo context stranske/Workflows

Excellent. I now have sufficient context to provide a comprehensive analysis. Let me summarize my findings:

Linked repositories findings

stranske/Workflows [::stranske/Workflows::]

Key Findings:

  1. Commit Span: The update moves from 6deed4d (February 2, 2026) to c2537cc (June 19, 2026) — spanning 1,688 commits representing a significant version progression from pre-1.15.0 to v1.15.2.

  2. Action Interface Stability: The setup-api-client action maintains backward compatibility:

    • Inputs remain unchanged — supports both JSON secrets via toJSON(secrets) and individual fallback inputs
    • Outputs remain unchanged — consistent three-output contract:
      • token_count: Number of tokens exported
      • available_tokens: Comma-separated token names
      • setup_contract: Machine-readable setup contract JSON
  3. Fallback Mechanism in agents-guard.yml: [::stranske/Workflows::]

    • The workflow first attempts to use the local action (./.github/actions/setup-api-client)
    • Falls back to the pinned external reference (stranske/Workflows/.github/actions/setup-api-client@v1) if local version is unavailable
    • Both paths maintain the same interface, so the update is safe for the fallback scenario
  4. Release History: Version 1.15.2 (the target commit) contains:

    • Bug fix: "guard runtime-ac external merge lanes" (commit 0fb465a)
    • No breaking changes documented in CHANGELOG.md
    • Multiple other features and fixes between 1.15.0-1.15.2, none affecting the action's contract
  5. Wide Usage: The setup-api-client action is imported in 20+ agent workflows across the repository, all using the same interface pattern. The stable outputs and inputs ensure consistent behavior across all consumers.

Conclusion: This is a straightforward dependency update with no API mismatches or breaking changes. The action interface is fully backward compatible between the two commits.

🔇 Additional comments (1)
.github/workflows/agents-guard.yml (1)

178-186: LGTM!

@renovate
renovate Bot force-pushed the renovate/stranske-workflows-digest branch from 290f063 to af99482 Compare June 20, 2026 01:59
@stranske
stranske merged commit 3004480 into main Jun 22, 2026
22 checks passed
@stranske
stranske deleted the renovate/stranske-workflows-digest branch June 22, 2026 03:02
stranske pushed a commit that referenced this pull request Jul 31, 2026
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant