Repository navigation
github_actions: pass home hostname to gh-actions-lock - #16504
Open
nodeselector wants to merge 3 commits into
Open
nodeselector wants to merge 3 commits into
nodeselector wants to merge 3 commits into
Conversation
Contributor
There was a problem hiding this comment.
馃煛 Changes recommended
The dry-run path still defaults tenant relocks to github.com, and the staging-only source build must be replaced before merging.
3 open findings
What changed in this PR
Adds hostname-aware GitHub Actions lockfile relocking, including *.ghe.com support and schema v0.0.3 compatibility.
Changes:
- Propagates the repository hostname and selects only its credential.
- Enables experimental
*.ghe.comlockfile handling and maps host errors. - Temporarily builds the hostname-aware CLI from source.
| File | Description |
|---|---|
updater/鈥媠pec/鈥媎ependabot/鈥媎ependency_change_builder_spec.rb |
Tests hostname option propagation. |
updater/鈥媗ib/鈥媎ependabot/鈥媎ependency_change_builder.rb |
Passes the source hostname to file updaters. |
github_actions/鈥媠pec/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媣ersion_gate_spec.rb |
Covers schema v0.0.3. |
github_actions/鈥媠pec/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媏nv_spec.rb |
Tests tenant credential selection. |
github_actions/鈥媠pec/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媍li_engine_spec.rb |
Tests hostname arguments and identity errors. |
github_actions/鈥媠pec/鈥媎ependabot/鈥媑ithub_actions/鈥媐ile_fetcher_spec.rb |
Covers experimental ghe.com fetching. |
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媣ersion_gate.rb |
Supports multiple schema versions. |
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媏rrors.rb |
Updates supported-version messaging. |
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媏nv.rb |
Selects credentials for the home host. |
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媍li_engine.rb |
Supplies hostname and maps identity failures. |
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媐ile_updater.rb |
Forwards hostname during relocking. |
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媐ile_fetcher.rb |
Gates *.ghe.com lockfiles experimentally. |
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媍onstants.rb |
Adds schema v0.0.3 support. |
github_actions/鈥婦ockerfile |
Builds the unreleased CLI revision from source. |
馃 Review effort: Balanced
馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Builds github/gh-actions-lock#137 at c5ee15d from source; no release exists for this SHA. Swap back to a release pin before review. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
nodeselector
force-pushed
the
nodeselector/gh-actions-lock-hostname
branch
from
October 8, 2026 21:41
743c5f2 to
8d124a5
Compare
nodeselector
force-pushed
the
nodeselector/gh-actions-lock-hostname
branch
from
October 8, 2026 21:50
8d124a5 to
9050ba9
Compare
nodeselector
marked this pull request as ready for review
October 8, 2026 21:53
| # Materialize the full onboarded closure so the lock remains intact, but fix | ||
| # only changed workflows so unrelated refs are not touched. | ||
| content = Lockfile::CliEngine.new(credentials).relock( | ||
| content = Lockfile::CliEngine.new(credentials, hostname: source_hostname).relock( |
The engine binds every pin with an omitted lockfile hostname to its home host. It runs in a temp dir with no git remote, so without --hostname the home host silently defaults to github.com. Pass --hostname from the job source and forward only a home-host token. Accept the v0.0.3 schema the engine now writes, and report lock host-identity failures as user-actionable rather than engine errors. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Fetch actions.lock for *.ghe.com sources under the existing github_actions_lockfile experiment, same as github.com. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
nodeselector
force-pushed
the
nodeselector/gh-actions-lock-hostname
branch
from
October 8, 2026 22:07
9050ba9 to
9b6de3b
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


What are you trying to accomplish?
Pass the repository's home host to
gh-actions-lockso lockfile relocks stay correct with the hostname-aware CLI (github/gh-actions-lock#137).The CLI binds every pin with an omitted lockfile
hostnameto its home host. Core runs it in a temp dir with no git remote, so the home host silently defaults togithub.com.--hostname, taken from the job source.v0.0.3. The CLI migratesv0.0.2and always writesv0.0.3.actions.lockfor*.ghe.comsources under the existinggithub_actions_lockfileexperiment, same as github.com. dependabot-api already sends it from the repo flagdependabot_github_actions_lockfile, so no API change is needed.Anything you want to highlight for special attention from reviewers?
Draft for staging only. The Dockerfile temporarily builds the CLI from source at
c5ee15d, because no release exists for that SHA yet. It moves back to a release pin before review.How will you know you've accomplished your goal?
Staging dry-runs against existing lockfiles. Relocks should keep the right host binding and write
v0.0.3.A
FileUpdaterspec checks thatsource_hostname: "tenant.ghe.com"reachesCliEngine.new(credentials, hostname: "tenant.ghe.com").Checklist