Skip to content

chore(deps): update ferrlabs/.github digest to b6a08e6 - #241

Merged
ferrlabs-renovate[bot] merged 1 commit into
mainfrom
renovate/ferrlabs-actions
Sep 24, 2026
Merged

ferrlabs-renovate[bot] merged 1 commit into
mainfrom
renovate/ferrlabs-actions

Conversation

@ferrlabs-renovate

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
FerrLabs/.github (changelog) workflow digest 006179d → b6a08e6

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@ferrlabs-renovate
ferrlabs-renovate Bot enabled auto-merge (squash) September 24, 2026 08:01
jobs:
release:
uses: FerrLabs/.github/.github/workflows/reusable-ferrflow-release.yml@006179d85612bca62c683001b983a3bfa98ca507 # main
uses: FerrLabs/.github/.github/workflows/reusable-ferrflow-release.yml@b6a08e6055076c18cfa7b8f80c9925275ed407fe # main
scan:
name: Secrets + CVE
uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@006179d85612bca62c683001b983a3bfa98ca507 # main
uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@b6a08e6055076c18cfa7b8f80c9925275ed407fe # main

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Digest bump for FerrLabs/.github, three callers repinned to the same new commit (b6a08e6). Only one commit sits between the old and new SHA: "keep a failed artifact upload from failing the gate that produced it" (#368).

What changed upstream: adds continue-on-error: true to several actions/upload-artifact steps (coverage handoffs in reusable-ci-go/node/rust.yml, SBOM upload in reusable-docker-build.yml, trufflehog findings upload in reusable-security-scan.yml) so an artifact-upload failure no longer fails the job that produced the artifact. No removed/renamed inputs, no new required inputs, no changed defaults.

What breaks here: of the three reusable workflows this repo calls (reusable-pr-title.yml, reusable-ferrflow-release.yml, reusable-security-scan.yml), only reusable-security-scan.yml was touched, and only the "Upload findings" (trufflehog) step's failure mode changed — it's now best-effort instead of fatal. That's strictly more lenient, no action needed here. reusable-pr-title.yml and reusable-ferrflow-release.yml weren't modified in this commit.

CI: all checks green except opengrep (SAST) still running at review time, nothing suggests it's related to this bump.

Uneventful, safe to merge.

@ferrlabs-renovate
ferrlabs-renovate Bot merged commit 5a541e8 into main Sep 24, 2026
11 checks passed
@ferrlabs-renovate
ferrlabs-renovate Bot deleted the renovate/ferrlabs-actions branch September 24, 2026 08:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant