Skip to content

chore(deps): bump petry-projects/.github-private/.github/workflows/pr-review.yml from 1.7.0 to 1.8.0 - #310

Merged
petry-projects-dependabot-automrg[bot] merged 5 commits into
mainfrom
dependabot/github_actions/petry-projects/dot-github-private/dot-github/workflows/pr-review.yml-1.8.0
Jun 23, 2026
Merged

chore(deps): bump petry-projects/.github-private/.github/workflows/pr-review.yml from 1.7.0 to 1.8.0#310
petry-projects-dependabot-automrg[bot] merged 5 commits into
mainfrom
dependabot/github_actions/petry-projects/dot-github-private/dot-github/workflows/pr-review.yml-1.8.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 22, 2026

Copy link
Copy Markdown
Contributor

Bumps petry-projects/.github-private/.github/workflows/pr-review.yml from 1.7.0 to 1.8.0.

Commits
  • ded84ce revert(dogfood): remove ci-status.sh dogfood comment + re-prove downstream-im...
  • bf04bea feat: implement issue #840 — [Phase 1] Author the LSP pilot scoping doc — lan...
  • 7a90255 test(dogfood): comment-only touch to exercise downstream-impact on next (#850)
  • 90876e1 scripts: make cut-release.sh executable (100644 -> 100755) (#834)
  • 761541f feat: implement issue #822 — Live idea:approved canary + Fleet Monitor covera...
  • 1ff137e docs(mcp-review): Context7 A/B eval findings + tool-name fix (#847)
  • 7f91b06 pr-review: dogfood ring-0 on @​pr-review/next (self-host canary) (#833)
  • 648b80b feat: add zero-auth Context7 MCP server to PR-review runtime (#826)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…-review.yml

Bumps [petry-projects/.github-private/.github/workflows/pr-review.yml](https://github.com/petry-projects/.github-private) from 1.7.0 to 1.8.0.
- [Commits](petry-projects/.github-private@ceab48a...ded84ce)

---
updated-dependencies:
- dependency-name: petry-projects/.github-private/.github/workflows/pr-review.yml
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependency update PRs security Security-related PRs and issues labels Jun 22, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner June 22, 2026 05:54
@dependabot dependabot Bot added dependencies Dependency update PRs security Security-related PRs and issues labels Jun 22, 2026
@petry-projects-dependabot-automrg
petry-projects-dependabot-automrg Bot enabled auto-merge (squash) June 22, 2026 05:54
…-github-private/dot-github/workflows/pr-review.yml-1.8.0
@don-petry
don-petry disabled auto-merge June 22, 2026 06:34
@don-petry

Copy link
Copy Markdown
Contributor

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
Files changed: None
Skipped (informational): 0
Status: Quality Gate passed — no changes needed.
```

@don-petry
don-petry enabled auto-merge (squash) June 22, 2026 06:35
…-github-private/dot-github/workflows/pr-review.yml-1.8.0
@don-petry
don-petry disabled auto-merge June 22, 2026 13:47
@don-petry
don-petry enabled auto-merge (squash) June 22, 2026 13:47
…-github-private/dot-github/workflows/pr-review.yml-1.8.0
@don-petry
don-petry disabled auto-merge June 22, 2026 19:40
@don-petry
don-petry enabled auto-merge (squash) June 22, 2026 19:41
…-github-private/dot-github/workflows/pr-review.yml-1.8.0
@sonarqubecloud

Copy link
Copy Markdown

@don-petry
don-petry disabled auto-merge June 22, 2026 22:13
@don-petry
don-petry enabled auto-merge (squash) June 22, 2026 22:13
@petry-projects-dependabot-automrg
petry-projects-dependabot-automrg Bot merged commit c0fcd97 into main Jun 23, 2026
22 of 23 checks passed
@petry-projects-dependabot-automrg
petry-projects-dependabot-automrg Bot deleted the dependabot/github_actions/petry-projects/dot-github-private/dot-github/workflows/pr-review.yml-1.8.0 branch June 23, 2026 04:14
don-petry pushed a commit that referenced this pull request Jun 23, 2026
…-review.yml from 1.7.0 to 1.8.0 (#310)

chore(deps): bump petry-projects/.github-private/.github/workflows/pr-review.yml

Bumps [petry-projects/.github-private/.github/workflows/pr-review.yml](https://github.com/petry-projects/.github-private) from 1.7.0 to 1.8.0.
- [Commits](petry-projects/.github-private@ceab48a...ded84ce)

---
updated-dependencies:
- dependency-name: petry-projects/.github-private/.github/workflows/pr-review.yml
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: dependabot-automerge-petry[bot] <270452309+dependabot-automerge-petry[bot]@users.noreply.github.com>
don-petry pushed a commit that referenced this pull request Jun 23, 2026
…-review.yml from 1.7.0 to 1.8.0 (#310)

chore(deps): bump petry-projects/.github-private/.github/workflows/pr-review.yml

Bumps [petry-projects/.github-private/.github/workflows/pr-review.yml](https://github.com/petry-projects/.github-private) from 1.7.0 to 1.8.0.
- [Commits](petry-projects/.github-private@ceab48a...ded84ce)

---
updated-dependencies:
- dependency-name: petry-projects/.github-private/.github/workflows/pr-review.yml
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: dependabot-automerge-petry[bot] <270452309+dependabot-automerge-petry[bot]@users.noreply.github.com>
don-petry pushed a commit that referenced this pull request Jun 23, 2026
…-review.yml from 1.7.0 to 1.8.0 (#310)

chore(deps): bump petry-projects/.github-private/.github/workflows/pr-review.yml

Bumps [petry-projects/.github-private/.github/workflows/pr-review.yml](https://github.com/petry-projects/.github-private) from 1.7.0 to 1.8.0.
- [Commits](petry-projects/.github-private@ceab48a...ded84ce)

---
updated-dependencies:
- dependency-name: petry-projects/.github-private/.github/workflows/pr-review.yml
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: dependabot-automerge-petry[bot] <270452309+dependabot-automerge-petry[bot]@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 27, 2026
…Dependabot drift)

Dependabot bumped the SHA-pinned caller from v1.7.0 (ceab48a) to v1.8.0
(ded84ce) in #310, dragging TalkTerm onto the unreleased 'next' channel ahead
of the stable promotion — stable is still v1.7.0. SHA-pinning a reusable makes
Dependabot's github-actions updater treat it as a versioned dependency and
auto-bump to the newest tag, bypassing the release-ring/channel strategy.

Switch the uses: ref to the non-semver moving tag @pr-review/stable (the pattern
the other consumers already use), which Dependabot leaves untouched. This
returns TalkTerm to stable (v1.7.0) and tracks future promotions centrally.
don-petry added a commit that referenced this pull request Jun 28, 2026
…sion drift) (#325)

* fix(pr-review): use moving pr-review/stable tag, not a SHA pin (stop Dependabot drift)

Dependabot bumped the SHA-pinned caller from v1.7.0 (ceab48a) to v1.8.0
(ded84ce) in #310, dragging TalkTerm onto the unreleased 'next' channel ahead
of the stable promotion — stable is still v1.7.0. SHA-pinning a reusable makes
Dependabot's github-actions updater treat it as a versioned dependency and
auto-bump to the newest tag, bypassing the release-ring/channel strategy.

Switch the uses: ref to the non-semver moving tag @pr-review/stable (the pattern
the other consumers already use), which Dependabot leaves untouched. This
returns TalkTerm to stable (v1.7.0) and tracks future promotions centrally.

* chore: apply manual instructions [skip ci-relay]

* fix(pr-review): add inline NOSONAR(githubactions:S7637) marker to uses: line

Adopt the org-wide canonical S7637 exemption (#549/#551): the channel-pinned
first-party reusable-ref uses: line carries an inline
# NOSONAR(githubactions:S7637) marker. This supersedes the per-file
sonar-project.properties approach and, unlike it, suppresses the rule at
analysis time — clearing BOTH the SonarCloud quality gate AND the GHAS
code-scanning SARIF alert that was keeping this PR's 'SonarCloud' check red and
making the pr-review agent skip on ci-failing.

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency update PRs security Security-related PRs and issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant