build(deps): bump taiki-e/install-action from 2.87.2 to 2.87.8 - #2191
build(deps): bump taiki-e/install-action from 2.87.2 to 2.87.8#2191dependabot[bot] wants to merge 1 commit into
Conversation
da2ce7
left a comment
There was a problem hiding this comment.
Reviewed at fc49c2da6b8e6b4e5cbda3b819041d759cfc16c3.
Verdict: comment, not approval — CI has not run at this head.
The change itself is correct and complete: three uses: lines bumped, exact version pin preserved (no moving @v2 tag), and no 2.87.2 reference left anywhere in the tree.
Upstream check between v2.87.2 (1ed6d7be) and v2.87.7 (84f5ac31): 33 files changed, none of them action runtime code — only manifests/*.json, the action's own CI, and CHANGELOG.md. Of the three tools these workflows install, the resolved versions are unchanged:
| tool | @v2.87.2 | @v2.87.7 |
|---|---|---|
grcov |
0.10.7 | 0.10.7 |
cargo-llvm-cov |
0.9.0 | 0.9.0 |
cargo-nextest |
0.9.143 | 0.9.143 |
(cargo-llvm-cov.json gained a 0.9.1 entry, but latest still points at 0.9.0.) So this bump is functionally inert for this repository.
Blocker — organization allowed-actions list. Three runs at this head ended in startup_failure with zero jobs created:
Testing(pull_request) — run34396702764Testing(push) — run34396698580Generate Coverage Report (PR)— run34396703553
The repository's allowed-actions list still carries the exact pattern taiki-e/install-action@v2.87.2, which does not admit @v2.87.7, so the workflows are rejected at parse time. Because no jobs are created, no check runs are either — gh pr checks 2191 lists 19 passing/skipped rows and exits 0, so this PR looks green while its three main workflows never started. Coverage is not in the list only because it triggers on push to develop; it carries the same pin and would break on the first push after merge.
Per .github/skills/dev/maintenance/update-github-workflow-actions/SKILL.md (step 4 and the Allowlist Failure Diagnosis section), the fix is on the organization side, not in this diff: a Torrust organization administrator needs to update the allowed-actions list in the organization Actions settings, replacing taiki-e/install-action@v2.87.2 with the scoped pattern taiki-e/install-action@v2.*. That unblocks this bump and every future Dependabot bump in the v2 line while keeping the exact pins in the workflows.
Once the allowlist is updated and the three runs are re-run green at this head, approval and ACK follow. Nothing is required from the author.
|
@dependabot rebase |
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.87.2 to 2.87.8. - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@v2.87.2...v2.87.8) --- updated-dependencies: - dependency-name: taiki-e/install-action dependency-version: 2.87.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
fc49c2d to
3ee022c
Compare
Bumps taiki-e/install-action from 2.87.2 to 2.87.8.
Release notes
Sourced from taiki-e/install-action's releases.
... (truncated)
Changelog
Sourced from taiki-e/install-action's changelog.
... (truncated)
Commits
d438492Release 2.87.8cf1fadeUpdateshfmt@latestto 3.14.17161449Updaterelease-plz@latestto 0.3.16258df4bbUpdateprotoc-gen-connect-openapi@latestto 0.26.033e9ffeUpdate oxfmt manifest60bf882Update kache manifest667469aUpdatedprint@latestto 0.57.4aa52fd6Updatecargo-llvm-cov@latestto 0.9.1834d344Updatecargo-crap@latestto 0.5.0097f1f0Updatecargo-binstall@latestto 1.23.0