Skip to content

Update github actions (main) (patch) - #3584

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main-main/patch-github-actions
Open

red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main-main/patch-github-actions

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
jlumbroso/free-disk-space action patch v1.3.1 → v1.3.2
oras-project/setup-oras action patch v2.0.1 → v2.0.2

Release Notes

jlumbroso/free-disk-space (jlumbroso/free-disk-space)

v1.3.2: — security fix and the decision records

Compare Source

Fixes the template-injection pattern in input handling (#​51, by @​nbuckwalt).

Also adds docs/adr/ — the reasoning behind this action: why it exists, what it inherited from apache/flink and ShubhamTatvamasi, what it deliberately does not do, and what is still open.

No behaviour changes. The swap-storage default change ships in the next release.

oras-project/setup-oras (oras-project/setup-oras)

v2.0.2

Compare Source

Highlights

  • Support ORAS CLI version(s): 1.3.4

What's Changed

New Contributors

Full Changelog: oras-project/setup-oras@v2.0.1...v2.0.2


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 1e6b4932-94ad-490b-9d5c-174e0b051c36
📥 Commits

Reviewing files that changed from the base of the PR and between 2afa4cc and 0e5b066.

📒 Files selected for processing (1)
  • .github/workflows/benchmark.yaml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The release and benchmark workflows update their Free Disk Space and ORAS actions to newer versions.

Changes

Workflow action updates

Layer / File(s) Summary
Update workflow action versions
.github/workflows/release.yaml, .github/workflows/benchmark.yaml
The release workflow updates jlumbroso/free-disk-space from v1.3.1 to v1.3.2. The benchmark workflow updates the ORAS setup action from v2.0.1 to v2.0.2.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

Suggested reviewers: joejstuart, dheerajodha

Merge Risk: ⚪ Minimal · up to 0e5b0

The updated actions match their workflow invocations, with no identified behavior mismatch that should block merging.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title refers to GitHub Actions updates, which matches the changes, but it does not identify the two actions or their version updates.
Description check ✅ Passed The description identifies both action version updates and includes relevant release notes and context. It does not use the template headings or provide a Tickets section, but it is mostly complete.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch from f0089ea to 34af133 Compare September 25, 2026 01:55
@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 25, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

A bot-authored single-line SHA pin bump in a protected CI workflow path; the CI_WORKFLOW_CHANGED and protected-path signals elevate Tier 1, but the minimal change size, benign automation authorship, and broad historical author diversity across the file keep the composite at moderate.

Previous run

Risk Assessment: moderate (2/5)

Details

Routine bot-authored action version bump (1 file, 2 lines) in a high-churn, multi-author CI workflow file; CI_WORKFLOW_CHANGED elevates Tier 1 but small change size, bot authorship, and absence of recent regressions keep the composite moderate.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Looks good to me

Previous run

Review

Routine Renovate SHA-pin bump of jlumbroso/free-disk-space from v1.3.1 to v1.3.2 in .github/workflows/release.yaml (single-line change; the new SHA 3f13feab2962a87273d379ebc36ea159527e6cc9 was verified as the v1.3.2 tag commit). Upstream release notes describe a security fix (template-injection pattern in input handling) with no behavior changes.

Findings

Info

  • [protected-path] .github/workflows/release.yaml — Change touches a governance path (.github/). Renovate is authorized to update GitHub Actions here via renovate.json at the repo root (which extends github>conforma/.github//config/renovate/renovate.json), so this is expected. Human approval is still required for protected-path changes.
  • [scope-authorization-implicit] N/A — Authorization inferred from the mechanical nature of the change (value-only / digest bump). No architectural review required.

@fullsend-ai-review fullsend-ai-review Bot added the requires-manual-review Review requires human judgment label Sep 25, 2026
@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
acceptance 54.51% <ø> (ø)
generative 12.25% <ø> (ø)
integration 23.56% <ø> (ø)
unit 72.24% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch 2 times, most recently from 13e91d1 to 5b2ebbc Compare September 29, 2026 01:55
Acepresso
Acepresso previously approved these changes Sep 30, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch 2 times, most recently from f06cb12 to c4fa30f Compare October 2, 2026 02:00
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 2:01 AM UTC · Completed 2:01 AM UTC

Commit: c4fa30f · View workflow run →

Effort: high

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch from c4fa30f to 483dfa7 Compare October 2, 2026 02:06
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 2:08 AM UTC · Completed 2:09 AM UTC

Commit: 483dfa7 · View workflow run →

Effort: high

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch from 483dfa7 to 2afa4cc Compare October 2, 2026 02:12
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 2:14 AM UTC · Completed 2:14 AM UTC

Commit: 2afa4cc · View workflow run →

Effort: high

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch from 2afa4cc to 0e5b066 Compare October 5, 2026 01:25
@red-hat-konflux red-hat-konflux Bot changed the title Update jlumbroso/free-disk-space action to v1.3.2 (main) Update github actions (main) (patch) Oct 5, 2026
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 1:27 AM UTC · Completed 1:27 AM UTC

Commit: 0e5b066 · View workflow run →

Effort: high

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch 2 times, most recently from 2084aaa to 75f5029 Compare October 5, 2026 01:35
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 1:37 AM UTC · Completed 1:37 AM UTC

Commit: 75f5029 · View workflow run →

Effort: high

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch from 75f5029 to 3b13275 Compare October 6, 2026 03:58
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 4:00 AM UTC · Completed 4:00 AM UTC

Commit: 3b13275 · View workflow run →

Effort: high

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/patch-github-actions branch from 3b13275 to 6024fdd Compare October 7, 2026 01:44
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 1:46 AM UTC · Completed 1:46 AM UTC

Commit: 6024fdd · View workflow run →

Effort: high

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

main renovate requires-manual-review Review requires human judgment risk/moderate PR risk: moderate size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant