From cd1d3295e591550fee7636adb4c3e0602f041cf1 Mon Sep 17 00:00:00 2001 From: YeonGyu-Kim Date: Fri, 9 Oct 2026 16:24:05 +0900 Subject: [PATCH 1/2] ci: refresh bun.lock on Dependabot npm branches --- .github/workflows/dependabot-bun-lock.yml | 60 +++++++++++++++++++++++ 1 file changed, 60 insertions(+) create mode 100644 .github/workflows/dependabot-bun-lock.yml diff --git a/.github/workflows/dependabot-bun-lock.yml b/.github/workflows/dependabot-bun-lock.yml new file mode 100644 index 0000000..fbecf6e --- /dev/null +++ b/.github/workflows/dependabot-bun-lock.yml @@ -0,0 +1,60 @@ +name: dependabot bun.lock + +# Dependabot's npm updater rewrites package.json and package-lock.json but never bun.lock, so `bun install +# --frozen-lockfile` in ci.yml fails on every npm bump before a test runs. This refreshes bun.lock on Dependabot's +# branches and re-runs CI on the new commit (a commit pushed with GITHUB_TOKEN starts no workflow by itself). + +on: + push: + branches: ["dependabot/npm_and_yarn/**"] + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + refresh: + name: refresh bun.lock + if: github.actor == 'dependabot[bot]' + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + contents: write + actions: write + steps: + - name: Checkout + uses: actions/checkout@v7 + with: + persist-credentials: false + + - name: Setup Bun + uses: oven-sh/setup-bun@v2 + with: + bun-version: 1.4.2 + + # Dependency lifecycle scripts never run here: this job holds a write token. + - name: Refresh bun.lock + run: bun install --ignore-scripts + + - name: Commit and re-run CI + env: + GH_TOKEN: ${{ github.token }} + BRANCH: ${{ github.ref_name }} + run: | + if git diff --quiet -- bun.lock; then + echo "bun.lock is already current" + exit 0 + fi + if [ -n "$(git status --porcelain -- . ':!bun.lock')" ]; then + git status --porcelain + echo "::error::bun install changed files other than bun.lock; not committing" + exit 1 + fi + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git commit -m "build(deps): refresh bun.lock" -- bun.lock + git push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "HEAD:refs/heads/${BRANCH}" + gh workflow run ci.yml --ref "$BRANCH" From 69302015d86e5c94cbaf6d672413eccb63d22413 Mon Sep 17 00:00:00 2001 From: YeonGyu-Kim Date: Fri, 9 Oct 2026 16:28:48 +0900 Subject: [PATCH 2/2] ci: pin actions by SHA in the bun.lock refresh job; job-level concurrency (review) --- .github/workflows/dependabot-bun-lock.yml | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/dependabot-bun-lock.yml b/.github/workflows/dependabot-bun-lock.yml index fbecf6e..bb13ea7 100644 --- a/.github/workflows/dependabot-bun-lock.yml +++ b/.github/workflows/dependabot-bun-lock.yml @@ -8,10 +8,6 @@ on: push: branches: ["dependabot/npm_and_yarn/**"] -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - permissions: contents: read @@ -21,21 +17,25 @@ jobs: if: github.actor == 'dependabot[bot]' runs-on: ubuntu-latest timeout-minutes: 10 + # Job-level, so a skipped run from someone else's push cannot cancel a refresh between its push and the CI dispatch. + concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true permissions: contents: write actions: write steps: - name: Checkout - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: persist-credentials: false - name: Setup Bun - uses: oven-sh/setup-bun@v2 + uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0 with: bun-version: 1.4.2 - # Dependency lifecycle scripts never run here: this job holds a write token. + # Pinned by SHA and run without dependency lifecycle scripts: this job holds a write token. - name: Refresh bun.lock run: bun install --ignore-scripts