Skip to content

experiment: add Docker-action form of dependabot-action - #669

Draft
jakecoffman wants to merge 1 commit into
mainfrom
jakecoffman/hosted-job-action
Draft

jakecoffman wants to merge 1 commit into
mainfrom
jakecoffman/hosted-job-action

Conversation

@jakecoffman

@jakecoffman jakecoffman commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

This is an experiment to integrate Dependabot CLI directly in a Docker-action.

The benefit is to remove the divergence between dependabot-action and Dependabot CLI. It's an alternative to the approach here:

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3761df46-553a-40d6-b34f-fcf5858d6d9d

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Volume forwarding can expose the Docker socket, and the mutable image reference defeats workflow version pinning.

2 open findings
What changed in this PR

Adds an experimental Docker-based GitHub Action that runs API-backed Dependabot jobs through the existing CLI infrastructure.

Changes:

  • Adds hosted-job API, configuration, credential masking, and volume translation.
  • Adds Docker packaging, release publishing, and integration CI.
  • Adds context-aware cancellation and resolved-credential handling.
File Description
internal/​infra/​run.go Adds context execution and resolved credentials.
internal/​infra/​run_test.go Tests cancellation and credentials.
Dockerfile Builds the Action image.
.dockerignore Excludes local artifacts.
action.yml Defines Action inputs and runtime.
cmd/​dependabot-action/​api.go Implements hosted-job API calls.
cmd/​dependabot-action/​api_test.go Tests API validation and retries.
cmd/​dependabot-action/​inputs.go Parses and validates inputs.
cmd/​dependabot-action/​inputs_test.go Tests inputs and volume translation.
cmd/​dependabot-action/​main.go Orchestrates jobs and secret masking.
cmd/​dependabot-action/​main_test.go Tests lifecycle and failures.
cmd/​dependabot-action/​mounts.go Translates nested-container mounts.
cmd/​dependabot-action/​docker_test.go Adds end-to-end Docker testing.
cmd/​dependabot-action/​testdata/​Dockerfile Builds test images.
cmd/​dependabot-action/​testdata/​proxy Provides the test proxy.
cmd/​dependabot-action/​testdata/​run Provides the test updater.
cmd/​dependabot-action/​testdata/​update-ca-certificates Stubs certificate setup.
.github/​workflows/​ci.yml Runs Action integration tests.
.github/​workflows/​release.yml Publishes and attests Action images.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread action.yml
required: false
runs:
using: docker
image: docker://ghcr.io/dependabot/cli-action:v1
Comment on lines +53 to +54
if best == nil || best.Type != mount.TypeBind {
return nil, fmt.Errorf("volume source %q is not inside an Action bind mount", source)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants