Skip to content

chore(deps): bump tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml from 61cd1338ca9dae8a25985c0a36ff7beb111449be to 72a347b6fff9fbc627436d7ee1589a9476e22725 - #30

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/tinyland-inc/ci-templates/dot-github/workflows/js-bazel-package.yml-72a347b6fff9fbc627436d7ee1589a9476e22725
Open

chore(deps): bump tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml from 61cd1338ca9dae8a25985c0a36ff7beb111449be to 72a347b6fff9fbc627436d7ee1589a9476e22725#30
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/tinyland-inc/ci-templates/dot-github/workflows/js-bazel-package.yml-72a347b6fff9fbc627436d7ee1589a9476e22725

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown

Bumps tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml from 61cd1338ca9dae8a25985c0a36ff7beb111449be to 72a347b6fff9fbc627436d7ee1589a9476e22725.

Changelog

Sourced from tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml's changelog.

Changelog

Format: Keep a Changelog. Versioning: SemVer 2.0.

[Unreleased]

[5.0.0] — 2026-09-02

Changed

  • TIN-2130/TIN-4249 ActionPlan/v4 schema 3 (targets ci-templates v5.0.0). Make result mandatory for every action, with the closed dispositions status-only and export-regular-files. Export mode requires exact Bazel target labels and 1--8 named output groups; it is carried only through the compiled client's verified ActionOutputSet/v1, never through workflow-side artifact discovery. Admit both Linux x86_64 and Darwin arm64 as abstract, provider-blind capability demand; absent signed supply fails resolution. The reusable spoke-ci-v4.yml dispatcher is byte-identical. The schema bytes are vendored from signed site.scaffold #163 commit 0a46c06b3415ba0b9dc4e8ff98173a6087d0ba68.

Removed

  • Treat schema 2 as historical v4.0.0 input, not a compatibility or local execution fallback. Schema-3 consumers must migrate atomically with their signed consumer-owned overlay digest and provider image; GF core and this repository continue to own no consumer instances.

Fixed

  • Correct the v4 release boundary after the first consumer canaries failed closed on an absent /usr/local/bin/gf-action-client: the immutable template requires the client at a provider-custodied image path, but its source release does not prove that provider rollout. The released 4.0.0 entry no longer calls its own tagged source a held, unreleased carrier.

[4.0.0] — 2026-09-01

Changed

  • TIN-2130 v4 action-fabric foundation (carrier comment a7fb6f87-5d45-45a6-bd99-136c4f461fbd). spoke-ci-v4.yml is now an exact-checkout, compiled-client dispatcher. One invocation selects one named action from the checked-in .github/lanes.json plan, and the workflow invokes /usr/local/bin/gf-action-client run once with the admitted source SHA. The plan is an admissibility boundary and does not claim one invocation executes every member. The admitted SHA is the exact owner-overlay identity: the pull-request head SHA for same-repository pull requests and github.sha for pushes. Unsupported

... (truncated)

Commits
  • 72a347b Merge pull request #148 from tinyland-inc/dependabot/github_actions/tinyland-...
  • 0067a1f Merge pull request #161 from tinyland-inc/codex/release-v5.0.0
  • 71f6e52 release: v5.0.0
  • 8e7a22b Merge pull request #160 from tinyland-inc/codex/tin-2130-schema3-output-set
  • f1a6f57 feat(v4): carry ActionPlan schema 3 (TIN-2130)
  • 419db67 Merge pull request #159 from tinyland-inc/codex/tin-4248-ci-templates-provide...
  • f2f5f48 docs(v4): state provider client boundary truthfully
  • 37da689 Merge pull request #158 from tinyland-inc/codex/tin-4249-ci-templates-v4-rele...
  • 8cf6d12 docs(release): match protected merge method
  • e258c56 release: v4.0.0
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…l-package.yml

Bumps [tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml](https://github.com/tinyland-inc/ci-templates) from 61cd1338ca9dae8a25985c0a36ff7beb111449be to 72a347b6fff9fbc627436d7ee1589a9476e22725.
- [Release notes](https://github.com/tinyland-inc/ci-templates/releases)
- [Changelog](https://github.com/tinyland-inc/ci-templates/blob/main/CHANGELOG.md)
- [Commits](tinyland-inc/ci-templates@61cd133...72a347b)

---
updated-dependencies:
- dependency-name: tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml
  dependency-version: 72a347b6fff9fbc627436d7ee1589a9476e22725
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants