Repository navigation
experiment: add Docker-action form of dependabot-action - #669
Draft
jakecoffman wants to merge 1 commit into
Draft
jakecoffman wants to merge 1 commit into
jakecoffman wants to merge 1 commit into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3761df46-553a-40d6-b34f-fcf5858d6d9d
There was a problem hiding this comment.
🟡 Changes recommended
Volume forwarding can expose the Docker socket, and the mutable image reference defeats workflow version pinning.
2 open findings
What changed in this PR
Adds an experimental Docker-based GitHub Action that runs API-backed Dependabot jobs through the existing CLI infrastructure.
Changes:
- Adds hosted-job API, configuration, credential masking, and volume translation.
- Adds Docker packaging, release publishing, and integration CI.
- Adds context-aware cancellation and resolved-credential handling.
| File | Description |
|---|---|
internal/infra/run.go |
Adds context execution and resolved credentials. |
internal/infra/run_test.go |
Tests cancellation and credentials. |
Dockerfile |
Builds the Action image. |
.dockerignore |
Excludes local artifacts. |
action.yml |
Defines Action inputs and runtime. |
cmd/dependabot-action/api.go |
Implements hosted-job API calls. |
cmd/dependabot-action/api_test.go |
Tests API validation and retries. |
cmd/dependabot-action/inputs.go |
Parses and validates inputs. |
cmd/dependabot-action/inputs_test.go |
Tests inputs and volume translation. |
cmd/dependabot-action/main.go |
Orchestrates jobs and secret masking. |
cmd/dependabot-action/main_test.go |
Tests lifecycle and failures. |
cmd/dependabot-action/mounts.go |
Translates nested-container mounts. |
cmd/dependabot-action/docker_test.go |
Adds end-to-end Docker testing. |
cmd/dependabot-action/testdata/Dockerfile |
Builds test images. |
cmd/dependabot-action/testdata/proxy |
Provides the test proxy. |
cmd/dependabot-action/testdata/run |
Provides the test updater. |
cmd/dependabot-action/testdata/update-ca-certificates |
Stubs certificate setup. |
.github/workflows/ci.yml |
Runs Action integration tests. |
.github/workflows/release.yml |
Publishes and attests Action images. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| required: false | ||
| runs: | ||
| using: docker | ||
| image: docker://ghcr.io/dependabot/cli-action:v1 |
Comment on lines
+53
to
+54
| if best == nil || best.Type != mount.TypeBind { | ||
| return nil, fmt.Errorf("volume source %q is not inside an Action bind mount", source) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This is an experiment to integrate Dependabot CLI directly in a Docker-action.
The benefit is to remove the divergence between dependabot-action and Dependabot CLI. It's an alternative to the approach here: