Skip to content

github_actions: pass home hostname to gh-actions-lock - #16504

Open
nodeselector wants to merge 3 commits into
dependabot:mainfrom
nodeselector:nodeselector/gh-actions-lock-hostname
Open

nodeselector wants to merge 3 commits into
dependabot:mainfrom
nodeselector:nodeselector/gh-actions-lock-hostname

Conversation

@nodeselector

@nodeselector nodeselector commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

What are you trying to accomplish?

Pass the repository's home host to gh-actions-lock so lockfile relocks stay correct with the hostname-aware CLI (github/gh-actions-lock#137).

The CLI binds every pin with an omitted lockfile hostname to its home host. Core runs it in a temp dir with no git remote, so the home host silently defaults to github.com.

Anything you want to highlight for special attention from reviewers?

Draft for staging only. The Dockerfile temporarily builds the CLI from source at c5ee15d, because no release exists for that SHA yet. It moves back to a release pin before review.

How will you know you've accomplished your goal?

Staging dry-runs against existing lockfiles. Relocks should keep the right host binding and write v0.0.3.

A FileUpdater spec checks that source_hostname: "tenant.ghe.com" reaches CliEngine.new(credentials, hostname: "tenant.ghe.com").

Checklist

  • I have run the complete test suite to ensure all tests and linters pass.
  • I have thoroughly tested my code changes to ensure they work as expected, including adding additional tests for new functionality.
  • I have written clear and descriptive commit messages.
  • I have provided a detailed description of the changes in the pull request, including the problem it addresses, how it fixes the problem, and any relevant details about the implementation.
  • I have ensured that the code is well-documented and easy to understand.

Copilot AI balanced review requested due to automatic review settings October 8, 2026 20:43
@github-actions github-actions Bot added the L: github:actions GitHub Actions label Oct 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃煛 Changes recommended

The dry-run path still defaults tenant relocks to github.com, and the staging-only source build must be replaced before merging.

3 open findings
What changed in this PR

Adds hostname-aware GitHub Actions lockfile relocking, including *.ghe.com support and schema v0.0.3 compatibility.

Changes:

  • Propagates the repository hostname and selects only its credential.
  • Enables experimental *.ghe.com lockfile handling and maps host errors.
  • Temporarily builds the hostname-aware CLI from source.
File Description
updater/鈥媠pec/鈥媎ependabot/鈥媎ependency_change_builder_spec.rb Tests hostname option propagation.
updater/鈥媗ib/鈥媎ependabot/鈥媎ependency_change_builder.rb Passes the source hostname to file updaters.
github_actions/鈥媠pec/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媣ersion_gate_spec.rb Covers schema v0.0.3.
github_actions/鈥媠pec/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媏nv_spec.rb Tests tenant credential selection.
github_actions/鈥媠pec/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媍li_engine_spec.rb Tests hostname arguments and identity errors.
github_actions/鈥媠pec/鈥媎ependabot/鈥媑ithub_actions/鈥媐ile_fetcher_spec.rb Covers experimental ghe.com fetching.
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媣ersion_gate.rb Supports multiple schema versions.
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媏rrors.rb Updates supported-version messaging.
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媏nv.rb Selects credentials for the home host.
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媗ockfile/鈥媍li_engine.rb Supplies hostname and maps identity failures.
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媐ile_updater.rb Forwards hostname during relocking.
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媐ile_fetcher.rb Gates *.ghe.com lockfiles experimentally.
github_actions/鈥媗ib/鈥媎ependabot/鈥媑ithub_actions/鈥媍onstants.rb Adds schema v0.0.3 support.
github_actions/鈥婦ockerfile Builds the unreleased CLI revision from source.

馃 Review effort: Balanced


馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread github_actions/Dockerfile Outdated
Comment thread github_actions/lib/dependabot/github_actions/file_updater.rb
Comment thread updater/spec/dependabot/dependency_change_builder_spec.rb
Builds github/gh-actions-lock#137 at c5ee15d from source; no release
exists for this SHA. Swap back to a release pin before review.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 8, 2026 21:41
@nodeselector
nodeselector force-pushed the nodeselector/gh-actions-lock-hostname branch from 743c5f2 to 8d124a5 Compare October 8, 2026 21:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃煛 Changes recommended

The Dockerfile still contains the explicitly temporary source build that must return to a checksummed release pin before merge.

1 open finding
2 resolved since last review

馃 Review effort: Balanced

Copilot AI balanced review requested due to automatic review settings October 8, 2026 21:50
@nodeselector
nodeselector force-pushed the nodeselector/gh-actions-lock-hostname branch from 8d124a5 to 9050ba9 Compare October 8, 2026 21:50
@nodeselector
nodeselector marked this pull request as ready for review October 8, 2026 21:53
@nodeselector
nodeselector requested a review from a team as a code owner October 8, 2026 21:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃煛 Changes recommended

The FileUpdater hostname handoff lacks direct regression coverage, and the Dockerfile remains staging-only.

1 open finding
1 resolved since last review

馃 Review effort: Balanced

# Materialize the full onboarded closure so the lock remains intact, but fix
# only changed workflows so unrelated refs are not touched.
content = Lockfile::CliEngine.new(credentials).relock(
content = Lockfile::CliEngine.new(credentials, hostname: source_hostname).relock(
nodeselector and others added 2 commits October 8, 2026 15:02
The engine binds every pin with an omitted lockfile hostname to its home
host. It runs in a temp dir with no git remote, so without --hostname
the home host silently defaults to github.com. Pass --hostname from the
job source and forward only a home-host token. Accept the v0.0.3 schema
the engine now writes, and report lock host-identity failures as
user-actionable rather than engine errors.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Fetch actions.lock for *.ghe.com sources under the existing
github_actions_lockfile experiment, same as github.com.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 8, 2026 22:07
@nodeselector
nodeselector force-pushed the nodeselector/gh-actions-lock-hostname branch from 9050ba9 to 9b6de3b Compare October 8, 2026 22:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃煛 Changes recommended

The Dockerfile still contains the explicitly temporary source build that must return to a checksummed release pin before merging.

1 open finding

馃 Review effort: Balanced

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

L: github:actions GitHub Actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants