Skip to content

chore(deps): bump tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml from 61cd1338ca9dae8a25985c0a36ff7beb111449be to a76a637c8d1b2abe5fade554185892cb37a09c66#22

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/tinyland-inc/ci-templates/dot-github/workflows/js-bazel-package.yml-a76a637c8d1b2abe5fade554185892cb37a09c66
Open

chore(deps): bump tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml from 61cd1338ca9dae8a25985c0a36ff7beb111449be to a76a637c8d1b2abe5fade554185892cb37a09c66#22
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/tinyland-inc/ci-templates/dot-github/workflows/js-bazel-package.yml-a76a637c8d1b2abe5fade554185892cb37a09c66

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 16, 2026

Copy link
Copy Markdown

Bumps tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml from 61cd1338ca9dae8a25985c0a36ff7beb111449be to a76a637c8d1b2abe5fade554185892cb37a09c66.

Changelog

Sourced from tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml's changelog.

Changelog

Format: Keep a Changelog. Versioning: SemVer 2.0.

[Unreleased]

[2.11.0] — 2026-07-10

Added

  • gf-credhelper-install composite action — installs the released gf-reapi-credhelper binary for the current runner platform from a pinned GloriousFlywheel release, verifies a caller-supplied SHA-256 before the binary reaches PATH, and exports GF_REAPI_CREDENTIAL_HELPER_BIN for flywheel-github-oidc-profile.sh plus the compatibility alias GF_REAPI_CREDENTIAL_HELPER. This is the reusable non-Nix consumer surface for the TIN-2724 enforce-cell :8980 proof path.

  • authorities.artifact_registry manifest key — new optional string authority in schemas/tinyland-repo-manifest.schema.json, distinct from authorities.package_registry. package_registry keeps its Bzlmod source-dependency-registry meaning (tinyland-inc/bazel-registry); artifact_registry names the published-artifact serving/gating surface (the Pulp registry — signed, versioned RELEASE artifacts over dnf/podman/https). Additive + optional (manifests without it still validate); resolves the long-standing package_registry naming overload before any consumer sets a value. Anchors the Cordillera registry charter (TIN-2718). The value lands separately in rockies/tinyland.repo.json.

Fixed

  • Org-namespaced Flywheel runner guardsflywheel-bazel and the cache-attachment contract now consume the same TIN-2353 runner-class grammar as nix-setup / lanes.schema.json, so tenant pools such as great-falls-tool-bus-nix and medical-massage-specialists-docker are treated as real cluster classes instead of being rejected by stale tinyland-only downstream guards.

  • Cloudflare Pages wrapper docs — the consumer example now matches the first live downstream adoption (GFTB PR #28): callers pass job-level contents: read / deployments: write, use secrets: inherit, and do not duplicate the reusable workflow's cloudflare-pages-${{ github.ref }} concurrency group. Duplicating that group deadlocks the caller against the called deploy job before any build step runs.

[2.10.0] — 2026-07-03

Added

... (truncated)

Commits
  • a76a637 release: v2.11.0 (#94)
  • 1efe3a3 feat(actions): gf-credhelper-install — pinned fetch + sha256-verify of the cr...
  • d50e853 feat(org-portability): de-tinyland lanes schema, nix-setup, credential helper...
  • 77ebde7 Merge pull request #89 from tinyland-inc/jess/tin-2718-artifact-registry-sche...
  • 282fbbf ci: add Dependabot config for automated dependency updates (#90)
  • 48983de feat(schema): add authorities.artifact_registry manifest key (TIN-2718)
  • b978515 docs: CF-Pages lane example must pass secrets explicitly, not inherit (#77)
  • 665d24e docs(spoke-deploy): document proven Cloudflare Pages wrapper (#75)
  • 2c07f97 release: v2.10.0
  • 5b21868 feat(spoke-deploy): reusable Cloudflare Pages deploy lane (DRY the hand-rolle...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…l-package.yml

Bumps [tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml](https://github.com/tinyland-inc/ci-templates) from 61cd1338ca9dae8a25985c0a36ff7beb111449be to a76a637c8d1b2abe5fade554185892cb37a09c66.
- [Release notes](https://github.com/tinyland-inc/ci-templates/releases)
- [Changelog](https://github.com/tinyland-inc/ci-templates/blob/main/CHANGELOG.md)
- [Commits](tinyland-inc/ci-templates@61cd133...a76a637)

---
updated-dependencies:
- dependency-name: tinyland-inc/ci-templates/.github/workflows/js-bazel-package.yml
  dependency-version: a76a637c8d1b2abe5fade554185892cb37a09c66
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants