Skip to content

chore: bump marocchino/sticky-pull-request-comment from 3.0.5 to 3.0.5 - #789

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/marocchino/sticky-pull-request-comment-3.0.5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/marocchino/sticky-pull-request-comment-3.0.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps marocchino/sticky-pull-request-comment from 3.0.5 to 3.0.5.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment) from 3.0.5 to 3.0.5.
- [Release notes](https://github.com/marocchino/sticky-pull-request-comment/releases)
- [Commits](marocchino/sticky-pull-request-comment@v3.0.5...5770ad5)

---
updated-dependencies:
- dependency-name: marocchino/sticky-pull-request-comment
  dependency-version: 3.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 21:46
@dependabot dependabot Bot added github_actions Pull requests that update GitHub Actions code dependencies Pull requests that update a dependency file labels Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Directly editing generated output leaves .anvil.lock inconsistent and disables automatic Anvil updates.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Pins the sticky-comment action to a commit SHA while retaining release 3.0.5.

Changes:

  • Replaces both v3.0.5 references with commit 5770ad5….
File Description
.github/​workflows/​anvil-pr-impl.yml Pins sticky-comment workflow steps by SHA.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

- name: Upsert anvil-semver advisory
if: always() && github.event_name == 'pull_request' && matrix.os == 'linux' && github.event.pull_request.head.repo.full_name == github.repository && hashFiles('target/anvil/comments/semver.md') != ''
uses: marocchino/sticky-pull-request-comment@v3.0.5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)
uses: marocchino/sticky-pull-request-comment@5770ad5eb8f42dd2c4f34da00c94c5381e49af88 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)
@martintmk martintmk added the human-review-required Human review required before automated approval. label Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ SemVer check advisory

Inconclusive comparisons

cargo semver-checks could not complete the following comparisons. These failures are informational because an unbuildable baseline is not evidence of a breaking API change.

metabench (exit 101)

     Cloning 03108d3ecb0bb57b3d23170468dd40224c2bb9fc
    Building metabench v0.1.1 (current)
error: running cargo-doc on crate 'metabench' failed with output:
-----
   Compiling proc-macro2 v1.0.107
   Compiling quote v1.0.47
   Compiling unicode-ident v1.0.26
   Compiling serde_core v1.0.229
   Compiling zmij v1.0.23
   Compiling serde v1.0.229
   Compiling serde_json v1.0.151
    Checking cfg-if v1.0.5
   Compiling libc v0.2.189
    Checking itoa v1.0.18
   Compiling syn v3.0.6
   Compiling syn v2.0.119
    Checking memchr v2.8.3
    Checking bitflags v2.13.2
   Compiling zerocopy v0.8.59
   Compiling equivalent v1.0.2
   Compiling hashbrown v0.17.1
   Compiling rustversion v1.0.23
   Compiling find-msvc-tools v0.1.14
   Compiling shlex v2.0.1
   Compiling semver v1.0.28
   Compiling winnow v1.0.4
   Compiling rustc_version v0.4.1
   Compiling cc v1.5.1
   Compiling toml_parser v1.1.3+spec-1.1.0
   Compiling serde_derive v1.0.229
   Compiling indexmap v2.14.2
   Compiling zerocopy-derive v0.8.59
   Compiling derive_more-impl v2.1.1
   Compiling autocfg v1.5.1
   Compiling toml_datetime v1.1.1+spec-1.1.0
   Compiling rustix v1.1.5
   Compiling toml_edit v0.25.15+spec-1.1.0
   Compiling num-traits v0.2.19
   Compiling alloca v0.4.0
    Checking either-or-both v0.3.1
   Compiling gungraun-macros v0.9.1
   Compiling proc-macro-error-attr3 v3.1.1
    Checking anstyle v1.0.14
    Checking clap_lex v1.1.1
    Checking ciborium-io v0.2.2
   Compiling getrandom v0.4.3
   Compiling cfg_aliases v0.2.2
    Checking regex-syntax v0.8.11
   Compiling thiserror v2.0.21
    Checking linux-raw-sys v0.12.1
   Compiling bincode-next v3.1.1
    Checking either v1.18.0
    Checking regex-automata v0.4.18
    Checking itertools v0.13.0
   Compiling nix v0.31.3
    Checking clap_builder v4.6.7
    Checking half v2.7.1
    Checking ciborium-ll v0.2.2
   Compiling proc-macro-error3 v3.1.1
    Checking rapidhash v4.5.1
   Compiling proc-macro-crate v3.5.0
   Compiling derive_more v2.1.1
   Compiling thiserror-impl v2.0.21
   Compiling gungraun v0.19.4
    Checking cast v0.3.0
   Compiling pastey v0.2.3
    Checking unty-next v0.1.2
    Checking same-file v1.0.6
    Checking walkdir v2.5.0
    Checking criterion-plot v0.8.2
    Checking clap v4.6.7
   Compiling metabench_macros_impl v0.1.1 (/home/runner/work/oxidizer/oxidizer/crates/metabench_macros_impl)
    Checking ciborium v0.2.2
    Checking regex v1.13.1
    Checking gungraun-runner v0.20.0
    Checking gungraun-runner v0.19.4
    Checking tinytemplate v1.2.1
    Checking folo_utils v0.1.14
    Checking nix v0.27.1
    Checking page_size v0.6.0
   Compiling metabench v0.1.1 (/home/runner/work/oxidizer/oxidizer/crates/metabench)
    Checking jiff-core v0.1.1
    Checking fastrand v2.5.0
    Checking oorandom v11.1.5
    Checking once_cell v1.21.4
    Checking anes v0.1.6
    Checking jiff v0.2.37
    Checking criterion v0.8.2
    Checking command-group v5.0.1
    Checking tempfile v3.27.0
    Checking gungraun-summary v6.0.0
error[E0432]: unresolved import `gungraun_runner::api::ValgrindTool`
  --> /home/runner/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/gungraun-summary-6.0.0/src/v6.rs:10:59
   |
10 |     CachegrindMetric, DhatMetric, ErrorMetric, EventKind, ValgrindTool,
   |                                                           ^^^^^^^^^^^^ no `ValgrindTool` in `api`

error[E0432]: unresolved imports `gungraun_runner::metrics::model::MetricsDiff`, `gungraun_runner::metrics::model::MetricsSummary`
  --> /home/runner/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/gungraun-summary-6.0.0/src/v6.rs:12:63
   |
12 | pub use gungraun_runner::metrics::model::{Metric, MetricKind, MetricsDiff, MetricsSummary};
   |                                                               ^^^^^^^^^^^  ^^^^^^^^^^^^^^ no `MetricsSummary` in `metrics::model`
   |                                                               |
   |                                                               no `MetricsDiff` in `metrics::model`

error[E0432]: unresolved imports `gungraun_runner::summary::model::Diffs`, `gungraun_runner::summary::model::FlamegraphSummary`, `gungraun_runner::summary::model::ProfileInfo`, `gungraun_runner::summary::model::SummaryFormat`, `gungraun_runner::summary::model::SummaryOutput`, `gungraun_runner::summary::model::ToolMetricSummary`
  --> /home/runner/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/gungraun-summary-6.0.0/src/v6.rs:14:38
   |
14 |     BenchmarkKind, BenchmarkSummary, Diffs, FlamegraphSummary, Profile, ProfileData, ProfileInfo,
   |                                      ^^^^^  ^^^^^^^^^^^^^^^^^                        ^^^^^^^^^^^ no `ProfileInfo` in `summary::model`
   |                                      |      |
   |                                      |      no `FlamegraphSummary` in `summary::model`
   |                                      no `Diffs` in `summary::model`
15 |     ProfilePart, ProfileTotal, Profiles, SCHEMA_VERSION, SummaryFormat, SummaryOutput,
   |                                                          ^^^^^^^^^^^^^  ^^^^^^^^^^^^^ no `SummaryOutput` in `summary::model`
   |                                                          |
   |                                                          no `SummaryFormat` in `summary::model`
16 |     ToolMetricSummary, ToolRegression,
   |     ^^^^^^^^^^^^^^^^^ no `ToolMetricSummary` in `summary::model`

For more information about this error, try `rustc --explain E0432`.
error: could not compile `gungraun-summary` (lib) due to 3 previous errors
warning: build failed, waiting for other jobs to finish...

-----

error: failed to build rustdoc for crate metabench v0.1.1
note: this is usually due to a compilation error in the crate,
      and is unlikely to be a bug in cargo-semver-checks
note: the following command can be used to reproduce the error:
      cargo new --lib example &&
          cd example &&
          echo '[workspace]' >> Cargo.toml &&
          cargo add --path /home/runner/work/oxidizer/oxidizer/crates/metabench &&
          cargo check &&
          cargo doc

error: aborting due to failure to build rustdoc for crate metabench v0.1.1

@martintmk

Copy link
Copy Markdown
Member

Posted by an AI agent

Automated fast-path stop at 70c2b01bcb740bba3230b4435ee3206e83ac65c9: .github/workflows/anvil-pr-impl.yml is cargo-anvil-generated and says direct edits stop automatic updates. This PR changes the generated workflow but leaves .anvil.lock at checksum e10f85f0…, while the current file hashes to c88e6438…. The full-SHA pin matches v3.0.5; please preserve it while updating the cargo-anvil source and regenerating/reconciling the lock before merge.

Checked head: 70c2b01. Human action: reconcile the generated workflow with its Anvil source and lock.

@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.0%. Comparing base (27a8b19) to head (70c2b01).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #789   +/-   ##
=======================================
  Coverage   100.0%   100.0%           
=======================================
  Files         738      736    -2     
  Lines       98623    98578   -45     
=======================================
- Hits        98623    98578   -45     
Flag Coverage Δ
linux 100.0% <ø> (ø)
linux-arm 100.0% <ø> (ø)
scheduled ?
windows 99.9% <ø> (-0.1%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@martintmk

Copy link
Copy Markdown
Member

AI review preparation has started for #789 at head 70c2b01bcb740bba3230b4435ee3206e83ac65c9.

The submitted GitHub review will contain the result.

@martintmk martintmk left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Posted by an AI agent

The review found no issues in workflow correctness, test coverage, or resilience. Consistency had one nit, noted inline. Performance, naming, telemetry, public contracts, and public API surface were not applicable to this workflow-only change. No code, tests, builds, benchmarks, or credentials-bearing code were executed. All reported CI checks were green. The pre-existing unresolved finding about editing generated workflow output without synchronizing .anvil.lock remains in its existing discussion and is not repeated.

- name: Upsert anvil-semver advisory
if: always() && github.event_name == 'pull_request' && matrix.os == 'linux' && github.event.pull_request.head.repo.full_name == github.repository && hashFiles('target/anvil/comments/semver.md') != ''
uses: marocchino/sticky-pull-request-comment@v3.0.5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)
uses: marocchino/sticky-pull-request-comment@5770ad5eb8f42dd2c4f34da00c94c5381e49af88 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Posted by an AI agent · Nit

The sticky-comment steps still say they are pinned by tag

Problem
Both references now use commit SHA 5770ad5eb8f42dd2c4f34da00c94c5381e49af88, but the inline comments still say “pinned by tag” and explain that GitHub locks the tag.

Why this matters
The annotations describe a tag pin, while the workflow directly pins the resolved commit.

Suggested fix
Update both comments to describe the commit-SHA pin, or remove the tag-lock explanation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code human-review-required Human review required before automated approval.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants