chore(ci): bump Quantum-L9/l9-ci-core/.github/actions/provision-sdk from f88116503430aa18992b70d8d31063e34ff97ef1 to 0d28395428426853c44825c4645c23ee8ace23b1 - #213
Conversation
Bumps [Quantum-L9/l9-ci-core/.github/actions/provision-sdk](https://github.com/quantum-l9/l9-ci-core) from f88116503430aa18992b70d8d31063e34ff97ef1 to 0d28395428426853c44825c4645c23ee8ace23b1. - [Commits](Quantum-L9/l9-ci-core@f881165...0d28395) --- updated-dependencies: - dependency-name: Quantum-L9/l9-ci-core/.github/actions/provision-sdk dependency-version: 0d28395428426853c44825c4645c23ee8ace23b1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
✅ PR reviewable size is within recommended limits |
L9 Audit Harness Report
Step Results
Architecture Audit Findings
See Spec Coverage
See Next StepsAll checks passed. Safe to merge. |
|
Closing Dependabot PR as part of Quantum-L9 org-wide cleanup. Human/agent PRs remain open. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
|
Replaced by the stacked PRs (this sibling is already closed):
Merge those bottom-up: 217 → 218 → 219. Do not squash 217 or 218 while a child is open. |
* chore(ci): collapse Dependabot pin refresh into one stack base Replace the overlapping #212/#213/#215/#216 siblings with a single bottom-of-stack commit: l9-ci-core pins to 0d28395, upload-artifact v7.0.1, and SPDX AND expressions on the license allow-list fallback so the observability layer can pass Dependency Review. Co-authored-by: Cursor <cursoragent@cursor.com> * chore(deps): bump observability group on the pin-refresh base structlog 26.1.0 and prometheus-client 0.26.0 from #211. Lands on chore/stack-ci-pins so the SPDX AND allow-list is already present. Co-authored-by: Cursor <cursoragent@cursor.com> * chore(ci): bump attest-build-provenance to v4.2.2 Independent docker-build.yml change from #214, stacked on the observability layer so the three PRs merge oldest-first without file fights. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ci): use compatible sdk-revision and keep SPDX AND licenses Baseline ratchet at l9-ci-core@0d28395 only lists b1a49141. Repo ALLOWED_LICENSES would drop Dual-license compounds from a fallback. Widen Docker/pip structlog to match Poetry 26.1.0. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ci): allow Dual-license observability via purl, hash-pin artifacts SPDX AND strings in allow-licenses did not match package Dual licenses and broke MIT matching for upload-artifact. Allow structlog and prometheus-client by purl; pin upload-artifact to v7.0.1 by hash. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps Quantum-L9/l9-ci-core/.github/actions/provision-sdk from f88116503430aa18992b70d8d31063e34ff97ef1 to 0d28395428426853c44825c4645c23ee8ace23b1.
Commits
0d28395Claude/pr remediation skill pfqo8f (#94)de469affeat(typescript-preset): stamp locked Biome contract instead of inventing bio...cd793fcdocs: footnote live@v1tip in AGENTS.md7fa8b63ci(self): beef up Core PR CI with lint, analysis dogfood, and security373bb6dci: bump actions/setup-python from 5.6.0 to 7.0.0 (#87)728fd86ci: bump ossf/scorecard-action (#86)12eb8d3deps(uv): bump pytest from 8.4.2 to 9.1.1 (#85)ade33c3deps(consumer-ci): bump pytest from 8.4.2 to 9.1.1 (#84)8bfaffedeps(consumer-ci): bump mypy from 1.19.0 to 2.3.0 (#82)5cb18b2deps(consumer-ci): bump the consumer-ci-minor-patch group with 3 updates (#81)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)