🤖 Generated by the Agentic Engineer
Problem
scripts/workflow-caller-pin-contract.test.sh requires every devantler-tech/actions caller to
pin the same commit and carry the same version comment. Three workflows call in:
| Workflow |
Job |
Reusable workflow |
.github/workflows/cd.yaml |
publish |
publish-app.yaml |
.github/workflows/release.yaml |
release |
create-release.yaml |
.github/workflows/template-sync.yaml |
template-sync |
template-sync.yaml |
This repository's .github/dependabot.yml has no groups: key on its github-actions
ecosystem, so Dependabot opens one PR per caller. Each bumps a single file and leaves the other
two behind, so each independently fails:
FAIL: every devantler-tech/actions caller must pin the same commit
That check is required, so CI - Required Checks fails and auto-merge can never complete. The PRs
deadlock each other: no single one can merge, and no merge order rescues it.
Why this repository still has it
devantler-tech/platform-tenant-template already fixed this. Its .github/dependabot.yml
carries a devantler-tech-actions group (plus a security-updates companion) with a long comment
recording the identical diagnosis — its own #156/#157/#158 each touched exactly one file.
That fix cannot reach this repository: .github/dependabot.yml is listed in
.templatesyncignore, because this tenant owns the file so it can add the npm and docker
ecosystems its stack needs. Template-sync therefore never overwrites it, and the grouping fix has
never arrived. The drift is invisible — nothing compares a sync-ignored file against the template.
Evidence
The v13.2.3 → v13.3.0 bump produced #219, #221 and #222 on 2026-09-05. All three armed auto-merge,
all three failed Workflow Caller Pins, and all three sat unmergeable. Reproduced locally: bumping
one caller alone fails with that exact message; bumping all three together passes.
This recurs on every devantler-tech/actions release, because the exclude cooldown rule
deliberately makes our own actions bump immediately.
Expected outcome
Dependabot raises a single PR that bumps every devantler-tech/actions caller together.
Acceptance criteria
- This repository's
.github/dependabot.yml groups all devantler-tech/* github-actions updates
into one pull request.
- A
devantler-tech/actions release produces exactly one PR touching all three callers, which
passes Workflow Caller Pins without intervention.
- The existing
exclude cooldown behaviour for devantler-tech/* is preserved, as are the npm
and docker ecosystems this tenant owns.
Notes
The current deadlock is cleared separately by #228, which bumps all three pins atomically — the
manual escalation the template's own comment prescribes. This issue is the recurrence fix.
A wider question this raises, not in scope here: no mechanism detects when a sync-ignored tenant
file drifts behind the template's version of the same file.
Problem
scripts/workflow-caller-pin-contract.test.shrequires everydevantler-tech/actionscaller topin the same commit and carry the same version comment. Three workflows call in:
.github/workflows/cd.yamlpublishpublish-app.yaml.github/workflows/release.yamlreleasecreate-release.yaml.github/workflows/template-sync.yamltemplate-synctemplate-sync.yamlThis repository's
.github/dependabot.ymlhas nogroups:key on itsgithub-actionsecosystem, so Dependabot opens one PR per caller. Each bumps a single file and leaves the other
two behind, so each independently fails:
That check is required, so
CI - Required Checksfails and auto-merge can never complete. The PRsdeadlock each other: no single one can merge, and no merge order rescues it.
Why this repository still has it
devantler-tech/platform-tenant-templatealready fixed this. Its.github/dependabot.ymlcarries a
devantler-tech-actionsgroup (plus asecurity-updatescompanion) with a long commentrecording the identical diagnosis — its own #156/#157/#158 each touched exactly one file.
That fix cannot reach this repository:
.github/dependabot.ymlis listed in.templatesyncignore, because this tenant owns the file so it can add thenpmanddockerecosystems its stack needs. Template-sync therefore never overwrites it, and the grouping fix has
never arrived. The drift is invisible — nothing compares a sync-ignored file against the template.
Evidence
The v13.2.3 → v13.3.0 bump produced #219, #221 and #222 on 2026-09-05. All three armed auto-merge,
all three failed
Workflow Caller Pins, and all three sat unmergeable. Reproduced locally: bumpingone caller alone fails with that exact message; bumping all three together passes.
This recurs on every
devantler-tech/actionsrelease, because theexcludecooldown ruledeliberately makes our own actions bump immediately.
Expected outcome
Dependabot raises a single PR that bumps every
devantler-tech/actionscaller together.Acceptance criteria
.github/dependabot.ymlgroups alldevantler-tech/*github-actions updatesinto one pull request.
devantler-tech/actionsrelease produces exactly one PR touching all three callers, whichpasses
Workflow Caller Pinswithout intervention.excludecooldown behaviour fordevantler-tech/*is preserved, as are thenpmand
dockerecosystems this tenant owns.Notes
The current deadlock is cleared separately by #228, which bumps all three pins atomically — the
manual escalation the template's own comment prescribes. This issue is the recurrence fix.
A wider question this raises, not in scope here: no mechanism detects when a sync-ignored tenant
file drifts behind the template's version of the same file.