diff --git a/.agents/pm/history/pm-github-11qm.jsonl b/.agents/pm/history/pm-github-11qm.jsonl new file mode 100644 index 0000000..7c25143 --- /dev/null +++ b/.agents/pm/history/pm-github-11qm.jsonl @@ -0,0 +1,5 @@ +{"ts":"2026-08-31T10:32:50.288Z","author":"pi-agent","author_source":"asserted","agent_harness":"pi","agent_model":"glm-5.2:cloud","agent_model_source":"environment","agent_instance":"129bad8965aa89eee6566ba7","agent_provenance":{"model":{"value":"glm-5.2:cloud","source":"environment"},"effort":null,"role":{"value":"implementer","source":"argv"},"topic":null},"op":"create","patch":[{"op":"add","path":"/metadata/id","value":"pm-github-11qm"},{"op":"add","path":"/metadata/title","value":"Group codeql-action bumps into one pull request to end the split-PR deadlock"},{"op":"add","path":"/metadata/description","value":"Dependabot opens github/codeql-action/init and github/codeql-action/analyze as two separate PRs; the two actions MUST be the same version in a workflow, so each PR alone mismatches the pair and the codeql check fails on BOTH, a permanent deadlock that must be broken by hand every time. Measured now: unbraind/pm-gantt-chart #87 (init 4.37.8->4.37.9) and #88 (analyze 4.37.8->4.37.9) each show FAILURE codeql with every other check green. Fix: add a groups block to .github/dependabot.yml so all github/codeql-action/* bumps arrive as ONE pull request, keeping init and analyze in sync."},{"op":"add","path":"/metadata/type","value":"Issue"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":2},{"op":"add","path":"/metadata/tags","value":[]},{"op":"add","path":"/metadata/created_at","value":"2026-08-31T10:32:50.288Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-08-31T10:32:50.288Z"},{"op":"add","path":"/metadata/author","value":"pi-agent"}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"6ace1f6eab004a760c94d1392805319836edcbce51156ac6c6f085961f80bcb3","item_hash_version":2,"message":""} +{"ts":"2026-08-31T10:32:50.915Z","author":"pi-agent","author_source":"asserted","agent_harness":"pi","agent_model":"glm-5.2:cloud","agent_model_source":"environment","agent_instance":"129bad8965aa89eee6566ba7","agent_provenance":{"model":{"value":"glm-5.2:cloud","source":"environment"},"effort":null,"role":null,"topic":null},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-08-31T10:32:50.915Z"},{"op":"add","path":"/metadata/assignee","value":"pi-agent"},{"op":"add","path":"/metadata/claim_principal","value":"pi-agent"}],"before_hash":"6ace1f6eab004a760c94d1392805319836edcbce51156ac6c6f085961f80bcb3","after_hash":"5cdb303d79941e444bf1e881239bcbbf37db80a3998e8928d10014ba3509b8ad","item_hash_version":2} +{"ts":"2026-08-31T10:32:50.960Z","author":"pi-agent","author_source":"asserted","agent_harness":"pi","agent_model":"glm-5.2:cloud","agent_model_source":"environment","agent_instance":"129bad8965aa89eee6566ba7","agent_provenance":{"model":{"value":"glm-5.2:cloud","source":"environment"},"effort":null,"role":null,"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-08-31T10:32:50.960Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"5cdb303d79941e444bf1e881239bcbbf37db80a3998e8928d10014ba3509b8ad","after_hash":"4901c17ddcf2ac3d342148a6415474d65feab6bee65278bf6c563b7907812025","item_hash_version":2} +{"ts":"2026-08-31T10:32:51.502Z","author":"pi-agent","author_source":"asserted","agent_harness":"pi","agent_model":"glm-5.2:cloud","agent_model_source":"environment","agent_instance":"129bad8965aa89eee6566ba7","agent_provenance":{"model":{"value":"glm-5.2:cloud","source":"environment"},"effort":null,"role":null,"topic":null},"op":"files_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-08-31T10:32:51.502Z"},{"op":"add","path":"/metadata/files","value":[{"path":".github/dependabot.yml","scope":"project"}]}],"before_hash":"4901c17ddcf2ac3d342148a6415474d65feab6bee65278bf6c563b7907812025","after_hash":"50724b05acc9b586e2c0566ac2e46b35b9a13cbe425e0fc20b12a0686583ce28","item_hash_version":2} +{"ts":"2026-08-31T10:32:52.159Z","author":"pi-agent","author_source":"asserted","agent_harness":"pi","agent_model":"glm-5.2:cloud","agent_model_source":"environment","agent_instance":"129bad8965aa89eee6566ba7","agent_provenance":{"model":{"value":"glm-5.2:cloud","source":"environment"},"effort":null,"role":{"value":"implementer","source":"argv"},"topic":null},"op":"close","patch":[{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-08-31T10:32:52.159Z"},{"op":"replace","path":"/metadata/status","value":"closed"},{"op":"add","path":"/metadata/closed_at","value":"2026-08-31T10:32:52.146Z"},{"op":"add","path":"/metadata/completed_at","value":"2026-08-31T10:32:52.146Z"},{"op":"add","path":"/metadata/close_reason","value":"Resolved by branch ci/group-codeql-action-bumps-into-one-pull-request landing a dependabot groups block that ships both codeql-action init and analyze bumps as one PR."}],"before_hash":"50724b05acc9b586e2c0566ac2e46b35b9a13cbe425e0fc20b12a0686583ce28","after_hash":"f04f7f802083ec39d0e7d74619d8d402274287f88b60ec6af69de5ae08717ed9","item_hash_version":2} diff --git a/.agents/pm/issues/pm-github-11qm.toon b/.agents/pm/issues/pm-github-11qm.toon new file mode 100644 index 0000000..d73af8b --- /dev/null +++ b/.agents/pm/issues/pm-github-11qm.toon @@ -0,0 +1,17 @@ +id: pm-github-11qm +title: Group codeql-action bumps into one pull request to end the split-PR deadlock +description: "Dependabot opens github/codeql-action/init and github/codeql-action/analyze as two separate PRs; the two actions MUST be the same version in a workflow, so each PR alone mismatches the pair and the codeql check fails on BOTH, a permanent deadlock that must be broken by hand every time. Measured now: unbraind/pm-gantt-chart #87 (init 4.37.8->4.37.9) and #88 (analyze 4.37.8->4.37.9) each show FAILURE codeql with every other check green. Fix: add a groups block to .github/dependabot.yml so all github/codeql-action/* bumps arrive as ONE pull request, keeping init and analyze in sync." +type: Issue +status: closed +priority: 2 +tags: [] +created_at: "2026-08-31T10:32:50.288Z" +updated_at: "2026-08-31T10:32:52.159Z" +closed_at: "2026-08-31T10:32:52.146Z" +completed_at: "2026-08-31T10:32:52.146Z" +claim_principal: pi-agent +author: pi-agent +files[1]{path,scope}: + .github/dependabot.yml,project +close_reason: Resolved by branch ci/group-codeql-action-bumps-into-one-pull-request landing a dependabot groups block that ships both codeql-action init and analyze bumps as one PR. +body: "" diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 044a124..2b876a3 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -11,3 +11,7 @@ updates: schedule: interval: "weekly" open-pull-requests-limit: 5 + groups: + codeql-action: + patterns: + - "github/codeql-action*" diff --git a/CHANGELOG.md b/CHANGELOG.md index aea968c..4d58a5f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## Unreleased + +### Fixed + +- Group codeql-action bumps into one pull request to end the split-PR deadlock ([pm-github-11qm](https://github.com/unbraind/pm-github/blob/main/.agents/pm/issues/pm-github-11qm.toon)) + ## 2026.8.31 - 2026-08-31 ### Fixed