Skip to content
This repository was archived by the owner on Aug 19, 2026. It is now read-only.

Pin gha-workflows workflows to v1.0.2 - #156

Closed
duynhne wants to merge 1 commit into
mainfrom
chore/gha-workflows-v1.0.2
Closed

duynhne wants to merge 1 commit into
mainfrom
chore/gha-workflows-v1.0.2

Conversation

@duynhne

@duynhne duynhne commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Moves all 13 duynhlab/gha-workflows references here from a mix of v1.0.0 and
v1.0.1 straight to v1.0.2 (725eb66).

Why not let Dependabot do it

Four open Dependabot PRs bump these to v1.0.1, and all four are BLOCKED:
sonar / SonarCloud Analysis and pr-checks / notify-pr-events fail on every
Dependabot run, because the Dependabot secrets store has no SONAR_TOKEN or
SLACK_BOT_TOKEN.

The fix for exactly that is in v1.0.2, not v1.0.1 — gha-workflows#108 adds
if: github.actor != 'dependabot[bot]' to pr-checks.yml, sonarqube.yml and
status.yml. So merging the v1.0.1 wave would leave the next wave red too.
Going straight to v1.0.2 ends it.

Risk

The whole v1.0.0 → v1.0.2 delta:

  1. codeql-action/upload-sarif SHA bump (patch within v4)
  2. the Dependabot skip guards above
  3. go-check.yml gains a cache-dependency-path input, defaulting to go.sum

docker-build-go.yml, docker-sign.yml and goreleaser.yml — the entire
release path — are byte-identical between v1.0.0 and v1.0.2.

Verification

  • 13/13 references at 725eb66; no other gha-workflows SHA remains in
    .github/workflows/
  • both files still parse
  • this PR is human-authored, so sonar and pr-checks/notify-pr-events run
    with real secrets and are expected to pass — that is the check to watch

Supersedes #152, #153, #154, #155, which will be closed once this merges.

Every reusable workflow here sat on a mix of v1.0.0 and v1.0.1. v1.0.2
skips the two secret-dependent jobs on Dependabot runs, which is what
paints every dependency PR red today: the Dependabot secrets store has
no SONAR_TOKEN or SLACK_BOT_TOKEN, so those jobs can never pass there.

This moves all thirteen references to v1.0.2 in one step rather than
letting Dependabot walk them to v1.0.1 first — that intermediate version
does not carry the fix, so the wave after it would be red as well.

The rest of the v1.0.0 to v1.0.2 delta is a codeql-action/upload-sarif
patch bump and a new backward-compatible go-check input. The release
path — docker-build-go, docker-sign, goreleaser — is byte-identical.
@sonarqubecloud

Copy link
Copy Markdown

@duynhne

duynhne commented Aug 16, 2026

Copy link
Copy Markdown
Contributor Author

Closing — auth-service is being retired, so it is dropped from the gha-workflows sweep.

@duynhne duynhne closed this Aug 16, 2026
@duynhne
duynhne deleted the chore/gha-workflows-v1.0.2 branch August 16, 2026 04:14
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant