Skip to content

Dependabot splits devantler-tech/actions bumps across PRs, deadlocking the same-commit pin contract #227

Description

@devantler

🤖 Generated by the Agentic Engineer

Problem

scripts/workflow-caller-pin-contract.test.sh requires every devantler-tech/actions caller to
pin the same commit and carry the same version comment. Three workflows call in:

Workflow Job Reusable workflow
.github/workflows/cd.yaml publish publish-app.yaml
.github/workflows/release.yaml release create-release.yaml
.github/workflows/template-sync.yaml template-sync template-sync.yaml

This repository's .github/dependabot.yml has no groups: key on its github-actions
ecosystem, so Dependabot opens one PR per caller. Each bumps a single file and leaves the other
two behind, so each independently fails:

FAIL: every devantler-tech/actions caller must pin the same commit

That check is required, so CI - Required Checks fails and auto-merge can never complete. The PRs
deadlock each other: no single one can merge, and no merge order rescues it.

Why this repository still has it

devantler-tech/platform-tenant-template already fixed this. Its .github/dependabot.yml
carries a devantler-tech-actions group (plus a security-updates companion) with a long comment
recording the identical diagnosis — its own #156/#157/#158 each touched exactly one file.

That fix cannot reach this repository: .github/dependabot.yml is listed in
.templatesyncignore, because this tenant owns the file so it can add the npm and docker
ecosystems its stack needs. Template-sync therefore never overwrites it, and the grouping fix has
never arrived. The drift is invisible — nothing compares a sync-ignored file against the template.

Evidence

The v13.2.3 → v13.3.0 bump produced #219, #221 and #222 on 2026-09-05. All three armed auto-merge,
all three failed Workflow Caller Pins, and all three sat unmergeable. Reproduced locally: bumping
one caller alone fails with that exact message; bumping all three together passes.

This recurs on every devantler-tech/actions release, because the exclude cooldown rule
deliberately makes our own actions bump immediately.

Expected outcome

Dependabot raises a single PR that bumps every devantler-tech/actions caller together.

Acceptance criteria

  • This repository's .github/dependabot.yml groups all devantler-tech/* github-actions updates
    into one pull request.
  • A devantler-tech/actions release produces exactly one PR touching all three callers, which
    passes Workflow Caller Pins without intervention.
  • The existing exclude cooldown behaviour for devantler-tech/* is preserved, as are the npm
    and docker ecosystems this tenant owns.

Notes

The current deadlock is cleared separately by #228, which bumps all three pins atomically — the
manual escalation the template's own comment prescribes. This issue is the recurrence fix.

A wider question this raises, not in scope here: no mechanism detects when a sync-ignored tenant
file drifts behind the template's version of the same file.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions