Skip to content

ci(dependabot): stop proposing openCoreEMR/actionlint bumps - #35

Merged
kojiromike merged 1 commit into
mainfrom
dependabot-ignore-actionlint
Sep 28, 2026
Merged

kojiromike merged 1 commit into
mainfrom
dependabot-ignore-actionlint

Conversation

@kojiromike

Copy link
Copy Markdown
Contributor

Adds a Dependabot ignore rule for openCoreEMR/actionlint.

The fork carries upstream tags as well as our -oce.N releases, and semver ranks v1.7.12 above v1.7.12-oce.1. Dependabot therefore proposes swapping the patched build for upstream, which rejects the client-id input on actions/create-github-app-token@v3 and fails lint (see #32). We bump the fork by hand until rhysd/actionlint#668 lands, then this rule goes away along with the fork.

The fork carries upstream tags alongside our -oce.N releases. Semver
ranks v1.7.12 above v1.7.12-oce.1, so Dependabot proposes swapping the
patched build for the upstream one, which rejects the client-id input on
actions/create-github-app-token@v3 and fails lint. Bump the fork by hand
until rhysd/actionlint#668 lands.

Assisted-by: Claude Code
@kojiromike
kojiromike merged commit b3a2410 into main Sep 28, 2026
1 check passed
@kojiromike
kojiromike deleted the dependabot-ignore-actionlint branch September 28, 2026 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant