Skip to content

chore(deps): bump NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml from 02bdb90f9f62b4b9d16b3c683bc0576976f36fde to c078ddcbcfb771f56a334184b7b6399cfd9c39c4 in the github-actions group across 1 directory - #33

Merged
rldyourmnd merged 2 commits into
mainfrom
dependabot/github_actions/github-actions-3f28ee9762
Sep 10, 2026
Merged

rldyourmnd merged 2 commits into
mainfrom
dependabot/github_actions/github-actions-3f28ee9762

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 1 update in the / directory: NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml.

Updates NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml from 02bdb90f9f62b4b9d16b3c683bc0576976f36fde to c078ddcbcfb771f56a334184b7b6399cfd9c39c4

Changelog

Sourced from NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml's changelog.

Changelog

Unreleased

  • GARM v0.2.1-nddev.94 binds stale scale-set job mutation to exact identity: check-run external_id, workflow_job.check_run_url, repository, exact attempt, numeric job ID and source SHA. A job name is never terminal proof. Missing fields, incomplete pagination, omitted or changing page totals, another attempt, a non-Actions producer and no exact match retain the intent. check_run_url and the check URL must share an https origin and repos/{owner}/{repo}/check-runs/{id} path; a missing check URL or a foreign host does not bind. GitHub 404 retains the intent and does not start the 15-minute access-refusal backoff used for 403/429. Scaling uses the latest MESSAGE statistics.TotalAssignedJobs; idle retirement requires a recent MESSAGE with messageID > 0 and re-checks that observation before RemoveRunner. Session-create zeros and 202/nil long-polls are not idle evidence. Start failure deletes the new message session and cancels the listener context. Listener JobCompleted with an empty runner name ends a delivery reservation and is not a REST workflow-job terminal; REST still-queued exact identity can clear that tombstone. A later same-run/name GUID is not aliased onto it. JobStarted of another GUID does not delete or rename an assigned waiter or copy its FIFO clock. A request-less JobAssigned yields occupancy only when a dispatchable JobAvailable would actually fit after that yield, including while that reservation is still unexpired; a quota-blocked available job does not evict a useful foreign bootstrap reservation. The original waiter and FIFO stay in the journal. Same-GUID JobAvailable keeps occupancy. An official build preserves the source tree when container stop is not proven. A replayed MESSAGE with the same session and messageID does not refresh idle-retirement freshness. A late message from a replaced session does not overwrite current demand. golang.org/x/text is v0.39.0. The .92 and .93 patches are unchanged. This is a source/artifact candidate, not a fleet rollout.

  • GARM v0.2.1-nddev.93 retires excess undemanded idle ephemeral JIT registrations through the Actions service RemoveRunner path (204 then 404) after two matching observations. REST busy must be explicit false; an omitted field is unknown, not idle. Scale-set statistics of all zeros are not proof that nothing is running. Identity changes, demand, min-idle, bootstrap/active states and JobStillRunningException refuse the delete. Provider delete remains GARM's ordinary absent-runner reconcile. Idle retirement is best-effort: a remote read or delete failure is a classified warning and cannot block absent-runner consolidation. The original consolidation lock lifetime is unchanged: runner Unlock stays deferred until consolidateRunnerState returns. Candidate age and min-idle are decided locally before any new API call. The .92 patches are unchanged. REST overlay fallback for acknowledged never-started jobs is not in this derivative: JobAssigned does not bind GitHub job ID or run attempt.

  • Ordinary merge in this repository does not require a general CI status check. Gate remains truthful advisory evidence.

... (truncated)

Commits
  • c078ddc Merge pull request #431 from NDDev-OpenNetwork/fix/garm-94-stale-job-identity...
  • b10db6b Merge pull request #432 from NDDev-OpenNetwork/fix/recovery-incident-retry-bu...
  • 913b483 fix(garm): freeze .94 identity origin binding and admissible yield
  • 9af80ad fix(recovery): bound overlapping incident retries to original plus two
  • ec7de1c fix(garm): yield bootstrap occupancy only to admissible jobs
  • a59488c fix(garm): close remaining .94 identity, session and build holes
  • 35a578c fix(garm): keep exact job identity and dispatch occupancy in .94
  • b20aa20 Merge pull request #430 from NDDev-OpenNetwork/feat/early-ci-feedback-20260907
  • a1a9026 chore(ci-feedback): bind final source validation in reusable caller
  • dc45eca Merge remote-tracking branch 'origin/main' into feat/early-ci-feedback-20260907
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ci-feedback.yml

Bumps the github-actions group with 1 update in the / directory: [NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml](https://github.com/nddev-opennetwork/github-actions).


Updates `NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml` from 02bdb90f9f62b4b9d16b3c683bc0576976f36fde to c078ddcbcfb771f56a334184b7b6399cfd9c39c4
- [Release notes](https://github.com/nddev-opennetwork/github-actions/releases)
- [Changelog](https://github.com/NDDev-OpenNetwork/github-actions/blob/main/CHANGELOG.md)
- [Commits](NDDev-Archive/github-actions-garm@02bdb90...c078ddc)

---
updated-dependencies:
- dependency-name: NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml
  dependency-version: c078ddcbcfb771f56a334184b7b6399cfd9c39c4
  dependency-type: direct:production
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from rldyourmnd as a code owner September 8, 2026 08:33
`config/reusable-workflow-pins.json` is the authority for every reusable
workflow this repository calls, and `scripts/ci/validate.sh` refuses any
workflow whose pin or trailing `# commit:` comment disagrees with it.

Dependabot knows about neither, so it rewrote only the `uses:` ref and left
both the comment and the registry on the previous commit. That is why every
Dependabot bump of this caller has failed `bootstrap-gate`, `bootstrap-ubuntu-plan`
and `bootstrap-macos-plan` while changing nothing about the workflow it pins.

`scripts/ci/validate.sh` now reports `ci-validate-ok`.

Claude-Session: https://claude.ai/code/session_01Dhii8pMkUcUEWKjhDwxzAX
@rldyourmnd
rldyourmnd merged commit 70a2f60 into main Sep 10, 2026
54 checks passed
@rldyourmnd
rldyourmnd deleted the dependabot/github_actions/github-actions-3f28ee9762 branch September 10, 2026 05:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant