chore(deps): update ferrlabs/.github digest to c4121e7 - #340
ferrlabs-renovate[bot] wants to merge 1 commit into
Conversation
SonarQube — aucune nouvelle issueComparaison entre le projet bac à sable de cette PR et la branche par défaut : SonarQube Community n'analyse pas les PR, ce delta est calculé côté CI. Détail |
There was a problem hiding this comment.
What changed: the only substantive commit in this digest range (FerrLabs/.github 539e9ac → 84f4447, #335) changes reusable-ci-node.yml's pnpm-version input default from '10' to ''. Empty now means pnpm/action-setup reads the pnpm version from the caller's package.json (packageManager or devEngines.packageManager) instead of hardcoding v10.
What breaks here: this repo's package.json has no packageManager field, only engines.pnpm: ">=9.0.0" (a range, not an exact pin), which pnpm/action-setup doesn't read. That's exactly why CI is failing.
Why CI fails: Test / Test & Build and Test / Quality (knip, madge, audit) both fail at the pnpm/action-setup step with: "Unable to determine pnpm version... provide it via the action's version input, or package.json's packageManager / devEngines.packageManager field." This is a real incompatibility introduced by the upstream default change, not a flake or a pre-existing failure.
Blocking: add a packageManager field to package.json (e.g. "packageManager": "pnpm@9.x.x", matching whatever pnpm version this repo currently builds with) before merging, or this and every future PR will fail CI until that's done.
9cbbdda to
4bb48c5
Compare
fb96c9f to
c343c73
Compare
10f8dd1 to
a51eab5
Compare
9ceaba1 to
dc10aa4
Compare
dc10aa4 to
6224be0
Compare
| packages: read | ||
| name: Test | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ci-node.yml@539e9aca37e08abde8d9cefbe13cd98fa62b1b41 # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ci-node.yml@c4121e79b9e15551efce374b7e9f4990667b9a36 # main |
| contents: write | ||
| id-token: write | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ferrflow-release.yml@539e9aca37e08abde8d9cefbe13cd98fa62b1b41 # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-ferrflow-release.yml@c4121e79b9e15551efce374b7e9f4990667b9a36 # main |
| scan: | ||
| name: Secrets + CVE | ||
| uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@539e9aca37e08abde8d9cefbe13cd98fa62b1b41 # main | ||
| uses: FerrLabs/.github/.github/workflows/reusable-security-scan.yml@c4121e79b9e15551efce374b7e9f4990667b9a36 # main |
There was a problem hiding this comment.
Follow-up: the digest range now extends past what I last reviewed (through FerrLabs/.github#337-343). Checked the new commits in that range:
- #337 bumps the pinned FerrFlow action to v7.21.1 in
reusable-ferrflow-release.yml— patch bump, no new inputs/secrets. - #339 drops the renovate workflow, #342 changes docker-build runner defaults — neither reusable is referenced by this repo's workflows (only
reusable-ci-node.yml,reusable-ferrflow-release.yml,reusable-pr-title.yml,reusable-security-scan.ymlare used), so both are no-ops here. - #340/#343 make the sonar reusable skip analysis on
pull_requestevents — this repo hasenable-sonar: true, but sonar isn't a required check, so this just means PR sonar comments stop; no breakage.
The blocking finding from my previous review is still open and unchanged: package.json still has no packageManager field, only engines.pnpm: ">=9.0.0", and Test / Test & Build and Test / Quality still fail at pnpm/action-setup with the same "No pnpm version is specified" error. Not repeating the detail here since nothing changed on that front, see the earlier review comment.
6224be0 to
5c5deff
Compare
5c5deff to
1399a41
Compare
This PR contains the following updates:
539e9ac→c4121e7Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.