This repository was archived by the owner on Aug 19, 2026. It is now read-only.
Conversation
Every reusable workflow here sat on a mix of v1.0.0 and v1.0.1. v1.0.2 skips the two secret-dependent jobs on Dependabot runs, which is what paints every dependency PR red today: the Dependabot secrets store has no SONAR_TOKEN or SLACK_BOT_TOKEN, so those jobs can never pass there. This moves all thirteen references to v1.0.2 in one step rather than letting Dependabot walk them to v1.0.1 first — that intermediate version does not carry the fix, so the wave after it would be red as well. The rest of the v1.0.0 to v1.0.2 delta is a codeql-action/upload-sarif patch bump and a new backward-compatible go-check input. The release path — docker-build-go, docker-sign, goreleaser — is byte-identical.
|
This was referenced Aug 16, 2026
Closed
Closed
Closed
Contributor
Author
|
Closing — auth-service is being retired, so it is dropped from the gha-workflows sweep. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Moves all 13
duynhlab/gha-workflowsreferences here from a mix of v1.0.0 andv1.0.1 straight to v1.0.2 (
725eb66).Why not let Dependabot do it
Four open Dependabot PRs bump these to v1.0.1, and all four are
BLOCKED:sonar / SonarCloud Analysisandpr-checks / notify-pr-eventsfail on everyDependabot run, because the Dependabot secrets store has no
SONAR_TOKENorSLACK_BOT_TOKEN.The fix for exactly that is in v1.0.2, not v1.0.1 — gha-workflows#108 adds
if: github.actor != 'dependabot[bot]'topr-checks.yml,sonarqube.ymlandstatus.yml. So merging the v1.0.1 wave would leave the next wave red too.Going straight to v1.0.2 ends it.
Risk
The whole v1.0.0 → v1.0.2 delta:
codeql-action/upload-sarifSHA bump (patch within v4)go-check.ymlgains acache-dependency-pathinput, defaulting togo.sumdocker-build-go.yml,docker-sign.ymlandgoreleaser.yml— the entirerelease path — are byte-identical between v1.0.0 and v1.0.2.
Verification
725eb66; no other gha-workflows SHA remains in.github/workflows/sonarandpr-checks/notify-pr-eventsrunwith real secrets and are expected to pass — that is the check to watch
Supersedes #152, #153, #154, #155, which will be closed once this merges.