From baaa0bced44007146db053f80cd804cc0c7dc275 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 07:21:47 +0000 Subject: [PATCH 1/2] chore(deps): bump docker/setup-qemu-action Bumps the actions group with 1 update: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action). Updates `docker/setup-qemu-action` from 4.2.0 to 4.4.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](https://github.com/docker/setup-qemu-action/compare/96fe6ef7f33517b61c61be40b68a1882f3264fb8...99012661954931238ded8c8b007157a8430204e1) --- updated-dependencies: - dependency-name: docker/setup-qemu-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 669daaa3..23efb446 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -484,7 +484,7 @@ jobs: cache: npm - run: npm ci - run: npm run build - - uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v3 + - uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v3 - name: Tag the checkout so install.sh has a pinned version to clone run: | set -euo pipefail From 1a6a267e8efab872621c96f95a1621be702714e7 Mon Sep 17 00:00:00 2001 From: operator Date: Sat, 3 Oct 2026 17:24:45 +0900 Subject: [PATCH 2/2] ci: move the reviewed workflow digest with the qemu pin `EXPECTED_CI_WORKFLOW_SHA256` locks the bytes of `ci.yml` that the release gate has reviewed, so any edit to that file -- including a Dependabot action bump -- fails 20 release-prerequisite tests until the digest moves with it. Dependabot cannot do that, which is why PR #1149 was red on a one-line change. The new pin was verified before being accepted: `refs/tags/v4` and `refs/tags/v4.4.0` in docker/setup-qemu-action both point at 99012661954931238ded8c8b007157a8430204e1, and v4.4.0 is the latest release. The comment on that line said `# v3` while the SHA it pinned was tagged v4.2.0, so it was wrong before this bump. Corrected to `# v4.4.0`, matching every other pin in the file, and the digest recomputed afterwards so the lock covers the bytes that will run. Limit: `EXPECTED_CI_WORKFLOW_SHA256` locks the reviewed bytes of ci.yml, so Dependabot cannot land a workflow bump on its own Warn: the comment on a pinned action is not evidence of the major in use -- this one read `# v3` while the SHA it pinned was tagged v4.2.0; confirm the tag through the API Blast: module Undo: easy Certainty: firm Record-Id: r-qemupinv44 Provenance: drafted --- .github/workflows/ci.yml | 2 +- scripts/check-exact-head-ci.mjs | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 23efb446..fa30b10f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -484,7 +484,7 @@ jobs: cache: npm - run: npm ci - run: npm run build - - uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v3 + - uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0 - name: Tag the checkout so install.sh has a pinned version to clone run: | set -euo pipefail diff --git a/scripts/check-exact-head-ci.mjs b/scripts/check-exact-head-ci.mjs index dbc7d2cf..b3f624ee 100644 --- a/scripts/check-exact-head-ci.mjs +++ b/scripts/check-exact-head-ci.mjs @@ -40,7 +40,7 @@ const CI_WORKFLOW_FILE_PATH = fileURLToPath(new URL(`../${CI_WORKFLOW_PATH}`, im // shell command; without this lock replacing every job body with `true` would // still look like a real successful run. Update deliberately with the CI // workflow when its reviewed job contract changes. -export const EXPECTED_CI_WORKFLOW_SHA256 = 'e82d9cdc4de7c5acad722fb887d41535b6c38ebd9cc057edc0df70c07f45ef00'; +export const EXPECTED_CI_WORKFLOW_SHA256 = '57d776e9b87a00ca7a11643d6ccb4098c2c6b8d82b9614c62e9e946456e81819'; // Fixed rather than inferred from returned jobs: absence must fail rather // than define itself away. `lint` only runs for pull requests and is therefore