Skip to content

chore(deps): update dependency node to v24 - #2396

Merged
stranske merged 2 commits into
mainfrom
renovate/node-24.x
Jun 16, 2026
Merged

chore(deps): update dependency node to v24#2396
stranske merged 2 commits into
mainfrom
renovate/node-24.x

Conversation

@renovate

@renovate renovate Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
node uses-with major 2024
node (source) major 2024

Release Notes

actions/node-versions (node)

v24.16.0: 24.16.0

Compare Source

Node.js 24.16.0

v24.15.0: 24.15.0

Compare Source

Node.js 24.15.0

v24.14.1: 24.14.1

Compare Source

Node.js 24.14.1

v24.14.0: 24.14.0

Compare Source

Node.js 24.14.0

v24.13.1: 24.13.1

Compare Source

Node.js 24.13.1

v24.13.0: 24.13.0

Compare Source

Node.js 24.13.0

v24.12.0: 24.12.0

Compare Source

Node.js 24.12.0

v24.11.1: 24.11.1

Compare Source

Node.js 24.11.1

v24.11.0: 24.11.0

Compare Source

Node.js 24.11.0

v24.10.0: 24.10.0

Compare Source

Node.js 24.10.0

v24.9.0: 24.9.0

Compare Source

Node.js 24.9.0

v24.8.0: 24.8.0

Compare Source

Node.js 24.8.0

v24.7.0: 24.7.0

Compare Source

Node.js 24.7.0

v24.6.0: 24.6.0

Compare Source

Node.js 24.6.0

v24.5.0: 24.5.0

Compare Source

Node.js 24.5.0

v24.4.1: 24.4.1

Compare Source

Node.js 24.4.1

v24.4.0: 24.4.0

Compare Source

Node.js 24.4.0

v24.3.0: 24.3.0

Compare Source

Node.js 24.3.0

v24.2.0: 24.2.0

Compare Source

Node.js 24.2.0

v24.1.0: 24.1.0

Compare Source

Node.js 24.1.0

v24.0.2: 24.0.2

Compare Source

Node.js 24.0.2

v24.0.1: 24.0.1

Compare Source

Node.js 24.0.1

v24.0.0: 24.0.0

Compare Source

Node.js 24.0.0

v22.22.3: 22.22.3

Compare Source

Node.js 22.22.3

v22.22.2: 22.22.2

Compare Source

Node.js 22.22.2

v22.22.1: 22.22.1

Compare Source

Node.js 22.22.1

v22.22.0: 22.22.0

Compare Source

Node.js 22.22.0

v22.21.1: 22.21.1

Compare Source

Node.js 22.21.1

v22.21.0: 22.21.0

Compare Source

Node.js 22.21.0

v22.20.0: 22.20.0

Compare Source

Node.js 22.20.0

v22.19.0: 22.19.0

Compare Source

Node.js 22.19.0

v22.18.0: 22.18.0

Compare Source

Node.js 22.18.0

v22.17.1: 22.17.1

Compare Source

Node.js 22.17.1

v22.17.0: 22.17.0

Compare Source

Node.js 22.17.0

v22.16.0: 22.16.0

Compare Source

Node.js 22.16.0

v22.15.1: 22.15.1

Compare Source

Node.js 22.15.1

v22.15.0: 22.15.0

Compare Source

Node.js 22.15.0

v22.14.0: 22.14.0

Compare Source

Node.js 22.14.0

v22.13.1: 22.13.1

Compare Source

Node.js 22.13.1

v22.13.0: 22.13.0

Compare Source

Node.js 22.13.0

v22.12.0: 22.12.0

Compare Source

Node.js 22.12.0

v22.11.0: 22.11.0

Compare Source

Node.js 22.11.0

v22.10.0: 22.10.0

Compare Source

Node.js 22.10.0

v22.9.0: 22.9.0

Compare Source

Node.js 22.9.0

v22.8.0: 22.8.0

Compare Source

Node.js 22.8.0

v22.7.0: 22.7.0

Compare Source

Node.js 22.7.0

v22.6.0: 22.6.0

Compare Source

Node.js 22.6.0

v22.5.1: 22.5.1

Compare Source

Node.js 22.5.1

v22.5.0: 22.5.0

Compare Source

Node.js 22.5.0

v22.4.1: 22.4.1

Compare Source

Node.js 22.4.1

v22.4.0: 22.4.0

Compare Source

Node.js 22.4.0

v22.3.0: 22.3.0

Compare Source

Node.js 22.3.0

v22.2.0: 22.2.0

Compare Source

Node.js 22.2.0

v22.1.0: 22.1.0

Compare Source

Node.js 22.1.0

v22.0.0: 22.0.0

Compare Source

Node.js 22.0.0

nodejs/node (node)

v24.16.0: 2026-05-21, Version 24.16.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [b267f6bca3] - (SEMVER-MINOR) crypto: implement randomUUIDv7() (nabeel378) #​62553
  • [ec2451b9cd] - (SEMVER-MINOR) debugger: add edit-free runtime expression probes to node inspect (Joyee Cheung) #​62713
  • [9705f628d9] - (SEMVER-MINOR) fs: add signal option to fs.stat() (Mert Can Altin) #​57775
  • [40ccfdecf9] - (SEMVER-MINOR) fs: expose frsize field in statfs (Jinho Jang) #​62277
  • [d7188af5c9] - (SEMVER-MINOR) http: harden ClientRequest options merge (Matteo Collina) #​63082
  • [aa1d8a9afc] - (SEMVER-MINOR) http: add req.signal to IncomingMessage (Akshat) #​62541
  • [6f37f7e240] - (SEMVER-MINOR) stream: propagate destruction in duplexPair (Ahmed Elhor) #​61098
  • [d14029be7f] - (SEMVER-MINOR) test_runner: support test order randomization (Pietro Marchini) #​61747
  • [d142c584cd] - (SEMVER-MINOR) test_runner: align mock timeout api (sangwook) #​62820
  • [01a9552585] - (SEMVER-MINOR) test_runner: add mock-timers support for AbortSignal.timeout (DeveloperViraj) #​60751
  • [00705a459a] - (SEMVER-MINOR) util: colorize text with hex colors (Guilherme Araújo) #​61556
Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Summary by CodeRabbit

  • Chores

    • Updated Node.js runtime from version 20 to version 24 across development containers, continuous integration workflows, and deployment templates.
    • Updated GitHub CLI feature version from 20 to 24 in development container configuration.
  • Tests

    • Updated test expectations to verify Node.js version 24 usage in workflows.

@renovate
renovate Bot requested a review from stranske as a code owner June 15, 2026 04:05
@renovate renovate Bot added the dependencies Dependency updates label Jun 15, 2026
@renovate
renovate Bot temporarily deployed to agent-standard June 15, 2026 04:05 Inactive
@github-actions github-actions Bot added the agents:allow-change Permit workflow edits when justification provided label Jun 15, 2026
@stranske-keepalive

Copy link
Copy Markdown
Contributor

Workflow source needed

PR #2396 needs either a linked GitHub issue or one valid non-issue Workflow Source before PR metadata automation can manage it safely.

Please do one of:

  • Add <!-- meta:issue:123 --> or a normal Closes #123 / Related to #123 line.
  • Check one Workflow Source option in the PR body.
  • Add a hidden marker such as <!-- workflow-source:local_request -->, <!-- workflow-source:manual_remote -->, <!-- workflow-source:review_followup -->, <!-- workflow-source:sync_campaign -->, or <!-- workflow-source:dependabot -->.
  • Add a workflow source label such as workflow:source-direct-pr, workflow:source-local-request, workflow:source-review-followup, workflow:source-sync, or workflow:no-automation.

Once a valid source is present, this warning will not be reposted.

@stranske-keepalive

stranske-keepalive Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

Automated Status Summary

Head SHA: c96a0da
Latest Runs: ⏳ pending — Gate
Required contexts: Gate / gate, Health 45 Agents Guard / guard
Required: core tests (3.12): ⏳ pending, core tests (3.13): ⏳ pending, docker smoke: ⏳ pending, gate: ⏳ pending

Workflow / Job Result Logs
(no jobs reported) ⏳ pending

Coverage Overview

  • Coverage history entries: 1

Coverage Trend

Metric Value
Current 70.30%
Baseline 85.00%
Delta -14.70%
Minimum 70.00%
Status ✅ Pass

Top Coverage Hotspots (lowest coverage)

File Coverage Missing
scripts/check_api_wrapper_guard.py 0.0% 123
scripts/cleanup_labels.py 0.0% 127
scripts/issue_dedup_smoke.py 0.0% 4
scripts/list_registered_consumer_repos.py 0.0% 33
scripts/repo_review_backlog_scan.py 0.0% 203
scripts/repo_review_queue_builder.py 0.0% 105
scripts/repo_review_round1_runner.py 0.0% 225
scripts/repo_review_round1_schema.py 0.0% 194
scripts/runner_lib/__main__.py 0.0% 3
scripts/update_langchain_versions.py 0.0% 34
scripts/validate_dependency_test_setup.py 0.0% 112
scripts/validate_template_completeness.py 0.0% 88
scripts/validate_template_sync.py 0.0% 77
scripts/validate_workflow_yaml.py 0.0% 98
scripts/repo_review_round2_schema.py 8.8% 185

Low Coverage Files (<50.0%)

File Coverage Missing
scripts/check_api_wrapper_guard.py 0.0% 123
scripts/cleanup_labels.py 0.0% 127
scripts/issue_dedup_smoke.py 0.0% 4
scripts/list_registered_consumer_repos.py 0.0% 33
scripts/repo_review_backlog_scan.py 0.0% 203
scripts/repo_review_queue_builder.py 0.0% 105
scripts/repo_review_round1_runner.py 0.0% 225
scripts/repo_review_round1_schema.py 0.0% 194
scripts/runner_lib/__main__.py 0.0% 3
scripts/update_langchain_versions.py 0.0% 34
scripts/validate_dependency_test_setup.py 0.0% 112
scripts/validate_template_completeness.py 0.0% 88
scripts/validate_template_sync.py 0.0% 77
scripts/validate_workflow_yaml.py 0.0% 98
scripts/repo_review_round2_schema.py 8.8% 185

Updated automatically; will refresh on subsequent CI/Docker completions.


Keepalive checklist

Scope

No scope information available

Tasks

  • No tasks defined

Acceptance criteria

  • No acceptance criteria defined

@renovate
renovate Bot temporarily deployed to agent-high-privilege June 15, 2026 04:06 Inactive
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from 9ed5426 to 16c6a0d Compare June 15, 2026 04:30
@renovate
renovate Bot temporarily deployed to agent-high-privilege June 15, 2026 04:32 Inactive
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from 16c6a0d to 9721b85 Compare June 15, 2026 05:50
@coderabbitai

coderabbitai Bot commented Jun 15, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Node.js is upgraded from version 20 to 24 across all actions/setup-node steps in every GitHub Actions workflow file, the shared agent-run-base composite action, the devcontainer github-cli feature pin, and the consumer-repo workflow templates. Template-drift allowlist fingerprints are updated to reflect the synchronized workflow changes, and a workflow test assertion is updated to expect the new Node.js 24 runtime.

Changes

Node.js 20 → 24 Upgrade

Layer / File(s) Summary
Devcontainer and shared composite action
.devcontainer/devcontainer.json, .github/actions/agent-run-base/action.yml
Bumps the ghcr.io/devcontainers/features/github-cli feature version to 24 and updates the shared composite action's Node.js setup step to node-version: 24.
Repository workflow version pins
.github/workflows/agents-*.yml, .github/workflows/health-*.yml, .github/workflows/reusable-*.yml, .github/workflows/pr-00-gate.yml, .github/workflows/selftest-ci.yml
Changes every actions/setup-node node-version from 20 to 24 across all agent, health, reusable CI, PR gate, keepalive, selftest, and cursor workflows.
Consumer-repo templates, drift allowlist, and test assertion
templates/consumer-repo/.github/workflows/*.yml, config/template-drift-allowlist.txt, tests/workflows/test_workflow_agents_consolidation.py
Applies the same node-version: 24 pin to the consumer-repo workflow templates for auto-pilot, weekly-metrics, and PR gate; updates template-drift-allowlist SHA-256 fingerprints for synchronized main vs. template workflow pairs; and updates the test_weekly_metrics_uploads_selector_report_on_failure assertion to expect Node.js 24.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related issues

  • #2210: Template synchronization and drift detection directly rely on the updated allowlist fingerprints; this PR refreshes those fingerprints to accommodate the coordinated Node.js 20 → 24 version bump across both main workflows and consumer-repo templates.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The pull request title 'chore(deps): update dependency node to v24' accurately and concisely summarizes the main change across all files—upgrading Node.js from v20 to v24.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/node-24.x

Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate
renovate Bot temporarily deployed to agent-high-privilege June 15, 2026 05:50 Inactive

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/agents-issue-optimizer.yml (1)

103-107: ⚠️ Potential issue | 🟠 Major

Pin all third-party actions to immutable SHAs, and sync main workflow with template.

The workflow uses three unpinned third-party actions: actions/checkout@v6, actions/setup-node@v6, and actions/setup-python@v6 (lines 101, 105, 125). Additionally, templates/consumer-repo/.github/workflows/agents-issue-optimizer.yml already pins checkout and setup-python to SHAs, revealing a sync drift where the main workflow is less secure than the template. Per coding guidelines, changes must be reflected in both locations.

🔒 Suggested changes
      - name: Checkout repository
        if: steps.check.outputs.should_run == 'true'
-       uses: actions/checkout@v6
+       uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3

      - name: Set up Node.js
        if: steps.check.outputs.should_run == 'true'
-       uses: actions/setup-node@v6
+       uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
         with:
           node-version: 24

      - name: Set up Python
        if: steps.check.outputs.should_run == 'true'
-       uses: actions/setup-python@v6
+       uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6
         with:
           python-version: '3.14'

Apply the same pinning in templates/consumer-repo/.github/workflows/agents-issue-optimizer.yml (which already has the first two pinned—ensure setup-node matches the main workflow if it's added to the template).

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/agents-issue-optimizer.yml around lines 103 - 107, The
workflow uses three unpinned third-party actions (actions/checkout,
actions/setup-node, and actions/setup-python) that should be pinned to immutable
commit SHAs instead of version tags for security. Replace the version tags (`@v6`)
with their specific commit SHAs for each of these three actions. Additionally,
ensure that the same pinned SHAs are consistently applied in both the main
workflow and the template workflow to maintain synchronization and security
standards across both locations.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/agents-63-issue-intake.yml:
- Around line 275-278: Pin the actions/setup-node action to a specific commit
SHA instead of using the mutable version tag to enhance supply-chain integrity.
Replace all occurrences of `actions/setup-node@v6` with
`actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6`. Make this
change at three locations: .github/workflows/agents-63-issue-intake.yml lines
275-278 (the uses statement in the first Set up Node.js step),
.github/workflows/agents-63-issue-intake.yml lines 1490-1493 (the uses statement
in the second Set up Node.js step), and
.github/workflows/agents-bot-comment-handler.yml lines 185-189 (the uses
statement in the Set up Node.js step in that workflow file).

In @.github/workflows/agents-weekly-metrics.yml:
- Around line 38-42: The node-version in two workflow files has been updated to
"24" but this breaks the enforced contract test in
tests/workflows/test_workflow_agents_consolidation.py line 424 which requires
node-version to be "20". Revert the node-version setting in
.github/workflows/agents-weekly-metrics.yml line 41 from "24" back to "20", and
also revert the same setting in
templates/consumer-repo/.github/workflows/agents-weekly-metrics.yml line 50 from
"24" back to "20" to maintain sync between the two files and satisfy the
contract test.

In `@templates/consumer-repo/.github/workflows/agents-weekly-metrics.yml`:
- Line 50: The Node version bump to "24" in the agents-weekly-metrics.yml
workflow at the node-version setting is breaking the weekly metrics validation
contract which is still expecting Node 20. Either update the weekly metrics
validation contract and test that explicitly checks against Node 20 to accept
Node 24, or revert the node-version in agents-weekly-metrics.yml back to "20" to
maintain compatibility with the existing contract. Choose one approach
consistently to resolve the merge-blocking selftest failure.

---

Outside diff comments:
In @.github/workflows/agents-issue-optimizer.yml:
- Around line 103-107: The workflow uses three unpinned third-party actions
(actions/checkout, actions/setup-node, and actions/setup-python) that should be
pinned to immutable commit SHAs instead of version tags for security. Replace
the version tags (`@v6`) with their specific commit SHAs for each of these three
actions. Additionally, ensure that the same pinned SHAs are consistently applied
in both the main workflow and the template workflow to maintain synchronization
and security standards across both locations.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 49df2b77-21ba-4bcb-9367-fcfdf6f08aa7

📥 Commits

Reviewing files that changed from the base of the PR and between 494a262 and 9721b85.

📒 Files selected for processing (20)
  • .devcontainer/devcontainer.json
  • .github/actions/agent-run-base/action.yml
  • .github/workflows/agents-63-issue-intake.yml
  • .github/workflows/agents-auto-pilot.yml
  • .github/workflows/agents-bot-comment-handler.yml
  • .github/workflows/agents-issue-optimizer.yml
  • .github/workflows/agents-keepalive-dispatch-handler.yml
  • .github/workflows/agents-keepalive-loop-reporter.yml
  • .github/workflows/agents-keepalive-loop.yml
  • .github/workflows/agents-weekly-metrics.yml
  • .github/workflows/health-75-api-rate-diagnostic.yml
  • .github/workflows/health-76-codex-cli-freshness.yml
  • .github/workflows/pr-00-gate.yml
  • .github/workflows/reusable-10-ci-python.yml
  • .github/workflows/reusable-20-pr-meta.yml
  • .github/workflows/reusable-cursor-run.yml
  • .github/workflows/selftest-ci.yml
  • templates/consumer-repo/.github/workflows/agents-auto-pilot.yml
  • templates/consumer-repo/.github/workflows/agents-weekly-metrics.yml
  • templates/consumer-repo/.github/workflows/pr-00-gate.yml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • stranske/Template (auto-detected)

Comment thread .github/workflows/agents-63-issue-intake.yml
Comment thread .github/workflows/agents-weekly-metrics.yml
Comment thread templates/consumer-repo/.github/workflows/agents-weekly-metrics.yml
@stranske
stranske temporarily deployed to agent-high-privilege June 16, 2026 20:32 — with GitHub Actions Inactive
@stranske
stranske enabled auto-merge (squash) June 16, 2026 20:33
@renovate

renovate Bot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@config/template-drift-allowlist.txt`:
- Around line 10-11: The allowlist entries at lines 10-11, 80-82, and 87-88
update main_sha256 without updating template_sha256 for workflows that have
consumer template counterparts, which masks drift instead of enforcing
consistency across consumer repos. Remove these entries from the allowlist, or
first propagate the workflow changes to
templates/consumer-repo/.github/workflows/* to match the main workflow updates,
then update both main_sha256 and template_sha256 together in the allowlist
entries according to the coding guideline that any change to consumer-used
workflows must be reflected in both the main workflows and the consumer template
workflows.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 4324a863-9761-4c96-be80-b6656842c43b

📥 Commits

Reviewing files that changed from the base of the PR and between 9721b85 and 0e1adba.

📒 Files selected for processing (5)
  • .github/workflows/agents-63-issue-intake.yml
  • .github/workflows/agents-bot-comment-handler.yml
  • .github/workflows/agents-issue-optimizer.yml
  • config/template-drift-allowlist.txt
  • tests/workflows/test_workflow_agents_consolidation.py
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • stranske/Template (auto-detected)

Comment on lines +10 to 11
main_sha256 = 8e552c2e168919da4265d78ae3983c21bced979c2896fb4fb928bbb0796c13a0
template_sha256 = 689d22e20cc6f21df006a2f7ed54924fc05d63adea5ef89251788f888f2a5495

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

Do not allowlist main-only workflow changes for consumer-synced pairs.

Line 10, Line 80, and Line 87 update main_sha256 while leaving template_sha256 unchanged for workflows that have consumer template counterparts. That masks drift instead of propagating the workflow change to templates/consumer-repo/.github/workflows/*, which can leave the 9 consumer repos on different behavior.

As per coding guidelines, “Any change to workflows that consumers use must be reflected in BOTH .github/workflows/ (main workflow) and templates/consumer-repo/.github/workflows/ (template).”

Also applies to: 80-82, 87-88

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@config/template-drift-allowlist.txt` around lines 10 - 11, The allowlist
entries at lines 10-11, 80-82, and 87-88 update main_sha256 without updating
template_sha256 for workflows that have consumer template counterparts, which
masks drift instead of enforcing consistency across consumer repos. Remove these
entries from the allowlist, or first propagate the workflow changes to
templates/consumer-repo/.github/workflows/* to match the main workflow updates,
then update both main_sha256 and template_sha256 together in the allowlist
entries according to the coding guideline that any change to consumer-used
workflows must be reflected in both the main workflows and the consumer template
workflows.

Source: Coding guidelines

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agents:allow-change Permit workflow edits when justification provided dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant