From 330f69089f7014ebbf6b82a893f83859575991b8 Mon Sep 17 00:00:00 2001 From: Ilyes512 Date: Fri, 25 Sep 2026 19:55:10 +0200 Subject: [PATCH 1/2] fix(merge): report the Merge Images check on dependabot pull requests The merge job was skipped for dependabot with a job-level `if`. GitHub does not evaluate the name of a job skipped that way, so the check came out as the literal `Merge / Merge Images${{ ... }}` instead of `Merge / Merge Images`. A ruleset requiring that check never saw it, and every dependabot pull request stayed blocked even though both builds had passed. The job now always runs and skips its steps instead, reporting success under its real name. A new `push` input controls it, defaulting to pushing except for dependabot, the same as build.yml. merge-go-cli.yml forwards it like build-go-cli.yml does. --- .github/workflows/merge-go-cli.yml | 7 +++++++ .github/workflows/merge.yml | 20 +++++++++++++++++++- docs/pipeline.md | 4 +++- docs/workflows.md | 5 ++++- 4 files changed, 33 insertions(+), 3 deletions(-) diff --git a/.github/workflows/merge-go-cli.yml b/.github/workflows/merge-go-cli.yml index 2625419..fe8b3b6 100644 --- a/.github/workflows/merge-go-cli.yml +++ b/.github/workflows/merge-go-cli.yml @@ -55,6 +55,12 @@ on: workflow sets, so they override them. type: string required: false + push: + description: >- + Create and push the manifest ("true"/"false"). Must match the build's push. Defaults to + pushing, except for dependabot. + type: string + required: false jobs: @@ -68,6 +74,7 @@ jobs: description: ${{ inputs.description }} version: ${{ inputs.version }} raw-tag: ${{ inputs.raw-tag }} + push: ${{ inputs.push }} flavor: | latest=false ${{ inputs.variant != '' && format('suffix=-{0},onlatest=true', inputs.variant) || '' }} diff --git a/.github/workflows/merge.yml b/.github/workflows/merge.yml index 567ca6d..6fd717f 100644 --- a/.github/workflows/merge.yml +++ b/.github/workflows/merge.yml @@ -39,24 +39,40 @@ on: description: Value for org.opencontainers.image.version type: string required: false + push: + description: >- + Create and push the manifest ("true"/"false"). Must match the build's push. Defaults to + pushing, except for dependabot. + type: string + required: false jobs: merge: name: Merge Images${{ inputs.target && format(' ({0})', inputs.target) || '' }} runs-on: ${{ inputs.runs-on }} - if: ${{ github.actor != 'dependabot[bot]' }} + # Skipped per step rather than per job: a job skipped by its `if` reports under its raw, + # unevaluated name, so it never satisfies a required "Merge Images" check. + env: + PUSH: ${{ inputs.push || github.actor != 'dependabot[bot]' }} steps: + - name: Skip merge + if: ${{ env.PUSH != 'true' }} + run: echo "::notice::The images were built without pushing, so there are no digests to merge." + - name: Checkout + if: ${{ env.PUSH == 'true' }} uses: actions/checkout@v7 - name: Image name id: image_name + if: ${{ env.PUSH == 'true' }} uses: ASzc/change-string-case-action@v8 with: string: ${{ inputs.image-name }} - name: Log in to the Container registry + if: ${{ env.PUSH == 'true' }} uses: docker/login-action@v4.6.0 with: registry: ghcr.io @@ -64,9 +80,11 @@ jobs: password: ${{ secrets.GITHUB_TOKEN }} - name: Set up Docker Buildx + if: ${{ env.PUSH == 'true' }} uses: docker/setup-buildx-action@v4 - name: Create Manifest + if: ${{ env.PUSH == 'true' }} uses: specsnl/github-actions/create-manifest@2.4.3 with: image-name: ${{ steps.image_name.outputs.lowercase }} diff --git a/docs/pipeline.md b/docs/pipeline.md index 592eea6..9112ff5 100644 --- a/docs/pipeline.md +++ b/docs/pipeline.md @@ -88,6 +88,8 @@ Dependabot pull requests only ever build; they never publish. - The registry login step in `build.yml` is skipped. - `build-image` defaults `push` to false, so the build runs but writes nothing to the registry. -- The whole `merge.yml` job is skipped, so nothing is tagged. +- `merge.yml` defaults `push` to false too, so its job runs but skips every step and nothing is tagged. It is not + skipped as a whole job: GitHub would report that under its unevaluated name, and a required `Merge Images` check would + never pass. The point is that the build itself still has to succeed before a dependency bump can be merged. diff --git a/docs/workflows.md b/docs/workflows.md index 40245fd..8641c72 100644 --- a/docs/workflows.md +++ b/docs/workflows.md @@ -27,7 +27,8 @@ The registry login step is skipped for dependabot, which is why `push` defaults ## `merge.yml` Merges the digests from `build.yml` into one tagged multi-arch manifest. Run it once, with `needs:` on the build job. -Skipped entirely for dependabot. +When `push` is off — by default for dependabot — the job still runs but skips every step, so a required `Merge Images` +check reports success. | Input | Type | Default | Description | |---------------|--------|------------|----------------------------------------------------------------------| @@ -40,6 +41,7 @@ Skipped entirely for dependabot. | `raw-tag` | string | `latest` | Tag used on `workflow_dispatch` runs | | `raw-tags` | string | — | Extra `metadata-action` tag directives (multiline), appended | | `flavor` | string | — | `metadata-action` flavor directives (multiline), i.e. `latest=false` | +| `push` | string | — | `"true"` / `"false"`; defaults to pushing, except for dependabot | See [How the image pipeline works](pipeline.md#tags) for what gets tagged by default. @@ -112,6 +114,7 @@ Fans out into one `merge.yml` call per PHP stage. | `raw-tag` | string | `latest` | Tag used on `workflow_dispatch` runs | | `raw-tags` | string | — | Extra tag directives, appended after this workflow's | | `flavor` | string | — | Extra flavor directives, appended after this workflow's, so they override | +| `push` | string | — | `"true"` / `"false"`; defaults to pushing, except for dependabot | ## `notify-slack-tag.yml` From 3dd651ec1b7f460bd746d6e895cfbaf0c2070f13 Mon Sep 17 00:00:00 2001 From: Ilyes512 Date: Fri, 25 Sep 2026 19:55:15 +0200 Subject: [PATCH 2/2] Bump internal version reference to 2.4.4 --- .github/workflows/build.yml | 2 +- .github/workflows/merge.yml | 2 +- README.md | 2 +- docs/actions.md | 4 ++-- docs/go-cli.md | 8 ++++---- docs/php.md | 4 ++-- docs/testing-images.md | 2 +- 7 files changed, 12 insertions(+), 12 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 7b9ea6b..1d1b03e 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -85,7 +85,7 @@ jobs: uses: docker/setup-buildx-action@v4 - name: Build and Push by digest - uses: specsnl/github-actions/build-image@2.4.3 + uses: specsnl/github-actions/build-image@2.4.4 with: dockerfile: ${{ inputs.dockerfile }} context: ${{ inputs.context }} diff --git a/.github/workflows/merge.yml b/.github/workflows/merge.yml index 6fd717f..71da3cb 100644 --- a/.github/workflows/merge.yml +++ b/.github/workflows/merge.yml @@ -85,7 +85,7 @@ jobs: - name: Create Manifest if: ${{ env.PUSH == 'true' }} - uses: specsnl/github-actions/create-manifest@2.4.3 + uses: specsnl/github-actions/create-manifest@2.4.4 with: image-name: ${{ steps.image_name.outputs.lowercase }} target: ${{ inputs.target }} diff --git a/README.md b/README.md index 3e2d134..cb7c5a9 100644 --- a/README.md +++ b/README.md @@ -3,7 +3,7 @@ This repository contains the Specsnl organisation collection of GitHub Actions workflows and composite actions that can be reused to automate various tasks in GitHub repositories. -Consumers pin by tag, i.e. `specsnl/github-actions/.github/workflows/build.yml@2.4.3`. +Consumers pin by tag, i.e. `specsnl/github-actions/.github/workflows/build.yml@2.4.4`. ## What is in here diff --git a/docs/actions.md b/docs/actions.md index c281ce4..053d800 100644 --- a/docs/actions.md +++ b/docs/actions.md @@ -9,7 +9,7 @@ Both assume the job has already checked out, logged in to the registry and set u ## `build-image` ```yaml -- uses: specsnl/github-actions/build-image@2.4.3 +- uses: specsnl/github-actions/build-image@2.4.4 ``` | Input | Default | Description | @@ -42,7 +42,7 @@ about conflicting outputs. With `load` on, the digest export and artifact upload ## `create-manifest` ```yaml -- uses: specsnl/github-actions/create-manifest@2.4.3 +- uses: specsnl/github-actions/create-manifest@2.4.4 ``` | Input | Default | Description | diff --git a/docs/go-cli.md b/docs/go-cli.md index 7722482..fb50e7c 100644 --- a/docs/go-cli.md +++ b/docs/go-cli.md @@ -21,7 +21,7 @@ permissions: jobs: build: - uses: specsnl/github-actions/.github/workflows/build-go-cli.yml@2.4.3 + uses: specsnl/github-actions/.github/workflows/build-go-cli.yml@2.4.4 strategy: fail-fast: false matrix: @@ -39,7 +39,7 @@ jobs: merge: needs: build - uses: specsnl/github-actions/.github/workflows/merge-go-cli.yml@2.4.3 + uses: specsnl/github-actions/.github/workflows/merge-go-cli.yml@2.4.4 with: runs-on: ubuntu-24.04 image-name: ghcr.io/specsnl/specs-cli @@ -123,7 +123,7 @@ Run the build and merge jobs once per variant, each with its own `target`: ```yaml build-alpine: - uses: specsnl/github-actions/.github/workflows/build-go-cli.yml@2.4.3 + uses: specsnl/github-actions/.github/workflows/build-go-cli.yml@2.4.4 strategy: fail-fast: false matrix: @@ -141,7 +141,7 @@ Run the build and merge jobs once per variant, each with its own `target`: merge-alpine: needs: build-alpine - uses: specsnl/github-actions/.github/workflows/merge-go-cli.yml@2.4.3 + uses: specsnl/github-actions/.github/workflows/merge-go-cli.yml@2.4.4 with: runs-on: ubuntu-24.04 image-name: ghcr.io/specsnl/specs-cli diff --git a/docs/php.md b/docs/php.md index 9c23cd5..349d2b1 100644 --- a/docs/php.md +++ b/docs/php.md @@ -8,7 +8,7 @@ what name. jobs: build: - uses: specsnl/github-actions/.github/workflows/build-php.yml@2.4.3 + uses: specsnl/github-actions/.github/workflows/build-php.yml@2.4.4 strategy: fail-fast: false matrix: @@ -24,7 +24,7 @@ jobs: merge: needs: build - uses: specsnl/github-actions/.github/workflows/merge-php.yml@2.4.3 + uses: specsnl/github-actions/.github/workflows/merge-php.yml@2.4.4 with: runs-on: ubuntu-24.04 image-name: ghcr.io/${{ github.repository }} diff --git a/docs/testing-images.md b/docs/testing-images.md index ced6967..9f7ce26 100644 --- a/docs/testing-images.md +++ b/docs/testing-images.md @@ -21,7 +21,7 @@ jobs: - uses: docker/setup-buildx-action@v4 - id: build - uses: specsnl/github-actions/build-image@2.4.3 + uses: specsnl/github-actions/build-image@2.4.4 with: platform: linux/amd64 image-name: ghcr.io/specsnl/specs-cli