Repository navigation
chore: bump marocchino/sticky-pull-request-comment from 3.0.5 to 3.0.5 - #789
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment) from 3.0.5 to 3.0.5. - [Release notes](https://github.com/marocchino/sticky-pull-request-comment/releases) - [Commits](marocchino/sticky-pull-request-comment@v3.0.5...5770ad5) --- updated-dependencies: - dependency-name: marocchino/sticky-pull-request-comment dependency-version: 3.0.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Directly editing generated output leaves .anvil.lock inconsistent and disables automatic Anvil updates.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Pins the sticky-comment action to a commit SHA while retaining release 3.0.5.
Changes:
- Replaces both
v3.0.5references with commit5770ad5….
| File | Description |
|---|---|
.github/workflows/anvil-pr-impl.yml |
Pins sticky-comment workflow steps by SHA. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| - name: Upsert anvil-semver advisory | ||
| if: always() && github.event_name == 'pull_request' && matrix.os == 'linux' && github.event.pull_request.head.repo.full_name == github.repository && hashFiles('target/anvil/comments/semver.md') != '' | ||
| uses: marocchino/sticky-pull-request-comment@v3.0.5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) | ||
| uses: marocchino/sticky-pull-request-comment@5770ad5eb8f42dd2c4f34da00c94c5381e49af88 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) |
|
|
Posted by an AI agent Automated fast-path stop at Checked head: 70c2b01. Human action: reconcile the generated workflow with its Anvil source and lock. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #789 +/- ##
=======================================
Coverage 100.0% 100.0%
=======================================
Files 738 736 -2
Lines 98623 98578 -45
=======================================
- Hits 98623 98578 -45
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
AI review preparation has started for #789 at head The submitted GitHub review will contain the result. |
martintmk
left a comment
There was a problem hiding this comment.
Posted by an AI agent
The review found no issues in workflow correctness, test coverage, or resilience. Consistency had one nit, noted inline. Performance, naming, telemetry, public contracts, and public API surface were not applicable to this workflow-only change. No code, tests, builds, benchmarks, or credentials-bearing code were executed. All reported CI checks were green. The pre-existing unresolved finding about editing generated workflow output without synchronizing .anvil.lock remains in its existing discussion and is not repeated.
| - name: Upsert anvil-semver advisory | ||
| if: always() && github.event_name == 'pull_request' && matrix.os == 'linux' && github.event.pull_request.head.repo.full_name == github.repository && hashFiles('target/anvil/comments/semver.md') != '' | ||
| uses: marocchino/sticky-pull-request-comment@v3.0.5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) | ||
| uses: marocchino/sticky-pull-request-comment@5770ad5eb8f42dd2c4f34da00c94c5381e49af88 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) |
There was a problem hiding this comment.
Posted by an AI agent · Nit
The sticky-comment steps still say they are pinned by tag
Problem
Both references now use commit SHA 5770ad5eb8f42dd2c4f34da00c94c5381e49af88, but the inline comments still say “pinned by tag” and explain that GitHub locks the tag.
Why this matters
The annotations describe a tag pin, while the workflow directly pins the resolved commit.
Suggested fix
Update both comments to describe the commit-SHA pin, or remove the tag-lock explanation.

Bumps marocchino/sticky-pull-request-comment from 3.0.5 to 3.0.5.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)