Skip to content

Update github actions (main) (patch) - #545

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/main-patch-github-actions
Sep 4, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/main-patch-github-actions

Conversation

@renovate

@renovate renovate Bot commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/checkout action patch v6.0.2v6.0.3
ossf/scorecard-action action patch v2.4.3v2.4.4

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source

ossf/scorecard-action (ossf/scorecard-action)

v2.4.4

Compare Source

What's Changed

This update bumps the Scorecard version to the v5.5.0 release. For a complete list of changes, please refer to the Scorecard v5.4.0 release notes and the Scorecard v5.5.0 release notes.

Full Changelog: ossf/scorecard-action@v2.4.3...v2.4.4


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) June 3, 2026 02:25
@github-actions

github-actions Bot commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://b5c4de0c.enterprise-contract.pages.dev

@renovate renovate Bot changed the title Update github actions to v6.0.3 (main) Update github actions (main) (patch) Jun 22, 2026
@renovate renovate Bot changed the title Update github actions (main) (patch) Update actions/checkout action to v6.0.3 (main) Jun 25, 2026
@renovate
renovate Bot force-pushed the renovate/main-patch-github-actions branch from 9333308 to 6476f86 Compare July 8, 2026 15:20
@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://a9deb436.enterprise-contract.pages.dev

@renovate
renovate Bot force-pushed the renovate/main-patch-github-actions branch from 6476f86 to a79e8a5 Compare July 24, 2026 02:32
@renovate renovate Bot changed the title Update actions/checkout action to v6.0.3 (main) Update github actions (main) (patch) Jul 24, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 24, 2026

Copy link
Copy Markdown

🤖 Review · ❌ Terminated · Started 2:33 AM UTC · Ended 2:41 AM UTC
Commit: 87c4a29 · View workflow run →

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://b89c88be.enterprise-contract.pages.dev

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure · Started 2:33 AM UTC · Completed 2:41 AM UTC
Commit: 87c4a29 · View workflow run →

@renovate
renovate Bot force-pushed the renovate/main-patch-github-actions branch from a79e8a5 to d037838 Compare September 1, 2026 13:42
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 1, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:43 PM UTC · Completed 2:04 PM UTC

Commit: 87c4a29 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.42

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://516690e6.enterprise-contract.pages.dev

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 1, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 1, 2026

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Tiny bot-authored CI workflow version bump (3 files, 8 lines) with low git churn; protected path count and CI workflow changes add moderate risk, but the minimal scope and bot authorship keep overall risk at moderate.

Previous run

Risk Assessment: moderate (2/5)

Details

Tiny bot-authored CI workflow version bump (3 files, 8 lines) with low git churn; protected path count and CI workflow changes add moderate risk, but the minimal scope and bot authorship keep overall risk at moderate.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 1, 2026

Copy link
Copy Markdown

Review

Findings

High

  • [protected-path] .github/workflows/build.yaml, .github/workflows/preview.yaml, .github/workflows/scorecards.yml — All 3 changed files are under the protected path .github/. This PR has no linked issue providing justification for modifying governance/infrastructure files. Human approval is always required for protected-path changes, regardless of change content.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run

Review

Findings

High

  • [protected-path] .github/workflows/build.yaml, .github/workflows/preview.yaml, .github/workflows/scorecards.yml — This PR modifies files under protected paths (.github/). The PR has no linked issue providing authorization for modifying governance or infrastructure files. Human approval is required for all protected-path changes.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-patch-github-actions branch from d037838 to c04aa9e Compare September 3, 2026 16:49
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026

Copy link
Copy Markdown

🤖 Review · ❌ Terminated · Started 4:50 PM UTC · Ended 5:05 PM UTC

Commit: ca5794c · View workflow run →

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://df05e1a5.enterprise-contract.pages.dev

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:50 PM UTC · Completed 5:05 PM UTC

Commit: ca5794c · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.70

@renovate
renovate Bot merged commit 6172dd2 into main Sep 4, 2026
11 checks passed
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 4, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 1:04 PM UTC · Completed 1:08 PM UTC

Commit: ca5794c · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.22

@fullsend-ai-retro

Copy link
Copy Markdown

Retro on PR #545 — a Renovate patch bump of actions/checkout (v6.0.2→v6.0.3) and ossf/scorecard-action (v2.4.3→v2.4.4): 3 files, 8 lines, all under .github/workflows/. Every issue I identified is already tracked, so no new proposals — this retro contributes evidence to existing issues instead.

Timeline

  • 2026-06-03: Renovate opens the PR.
  • 2026-07-24: First review agent run 30061904278 — agent itself exits 0 with an Approve verdict in ~6m, but the post-agent target-repo cleanup fails with permission denied removing vendored files (antora/supplemental-ui/css/vendor/tabs.css, website/layouts/index.html), so the workflow exits 1 and the correct verdict is never posted.
  • 2026-09-01: Re-review run 33515044548 — 21m18s, $4.42, opus/high. Correctly classifies the PR as a mechanical Renovate patch bump but declines to inspect renovate.json ("reconciliation doesn't apply here") and emits a high-severity protected-path finding because .github/ was touched with no linked issue → CHANGES_REQUESTED.
  • 2026-09-03: Push of ca5794c; run 33780970249 reproduces the same protected-path finding at cost $2.70.
  • 2026-09-04: Human robnester-rh approves and merges. Total agent spend on this trivial bot bump: ~$9.17 across three runs, ~2 months wall time from open to merge.

Findings already covered by existing issues (skipping proposals)

  1. Post-agent cleanup permission-denied lost a correct verdict. Same failure mode as fullsend-ai/fullsend#5460 (closed 2026-07-22, unlinkat ... permission denied on read-only target-repo files) and #5529 (closed 2026-08-18, website/.gitignore cleanup permission denied). This PR's 2026-07-24 run pre-dates both closures, so it is likely resolved already; no re-open needed unless the pattern recurs on a post-2026-08-18 run.

  2. Protected-path high-severity false positive on Renovate patch bumps to .github/workflows/. Directly covered by fullsend-ai/fullsend#4387, #2588, #5370, #5369, #3164, #2614, and fullsend-ai/agents#257. New evidence: two consecutive runs on the same commit produced the identical governance-only finding, and the review agent explicitly reasoned itself out of consulting renovate.json as authorization evidence. This is a concrete data point for #4387 / agents#257: the agent recognizes the bot-patch pattern and still cannot self-authorize.

  3. Cost/effort mismatch on mechanical bumps. $4.42 (opus/high, 21 min, 3 parallel sub-agents) to review 8 lines of a patch version bump. Directly on-topic for fullsend-ai/agents#513 (short-circuit to lightweight mode after classifying as mechanical dependency bump) and #257 (pre-review early exit for bot dependency updates). New evidence: even after the risk-assessment sub-agent labels the PR "moderate — tiny bot-authored CI workflow version bump," the full opus/high review still runs.

Autonomy readiness note. Human review here was a bare approval with no comments — a reasonable outcome for a 2-line uses: bump. The review agent has all the information needed to reach the same verdict (author=Renovate, patch-only version delta, no code changes) but is blocked by the protected-path rule with no bot exemption path. Progress on #4387 / #5370 / agents#257 is what would close this gap; there is nothing repo-specific for conforma/conforma.github.io to fix.

No new issues filed.

@renovate
renovate Bot deleted the renovate/main-patch-github-actions branch September 4, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant