Skip to content

chore(deps): bump lewagon/wait-on-check-action from 1.3.4 to 1.5.0 - #94

Merged
hyperpolymath merged 3 commits into
mainfrom
dependabot/github_actions/lewagon/wait-on-check-action-1.5.0
Mar 22, 2026
Merged

hyperpolymath merged 3 commits into
mainfrom
dependabot/github_actions/lewagon/wait-on-check-action-1.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 22, 2026

Copy link
Copy Markdown
Contributor

Bumps lewagon/wait-on-check-action from 1.3.4 to 1.5.0.

Release notes

Sourced from lewagon/wait-on-check-action's releases.

v1.5.0

Added

  • Add fail-on-no-checks option (#133)

Fixed

  • Bump rexml to 3.4.2 (#128)

v1.4.1

Fixed

  • Linux ARM64 support

v1.4.0

Added

  • Add class docs
  • Add frozen_string_literal comments

Removed

  • Remove OpenStruct instances
  • Remove Double quotes
  • Remove Double assertions
  • Remove allow_any uses

Fixed

  • Fix spelling mistakes
  • Fix CI gem caching
  • Convert config.verbose to a boolean
  • Bump rexml to 3.3.9
Changelog

Sourced from lewagon/wait-on-check-action's changelog.

Changelog

Unreleased

v1.5.0 - 2026-01-25

Added

  • Add fail-on-no-checks option

Fixed

  • Bump rexml to 3.4.2

v1.4.1 - 2025-09-21

Fixed

  • Linux ARM64 support

v1.4.0 - 2025-06-27

Added

  • Add class docs
  • Add frozen_string_literal comments

Removed

  • Remove OpenStruct instances
  • Remove Double quotes
  • Remove Double assertions
  • Remove allow_any uses

Fixed

  • Fix spelling mistakes
  • Fix CI gem caching
  • Convert config.verbose to a boolean
  • Bump rexml to 3.3.9

v1.3.4 - 2024-04-04

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lewagon/wait-on-check-action](https://github.com/lewagon/wait-on-check-action) from 1.3.4 to 1.5.0.
- [Release notes](https://github.com/lewagon/wait-on-check-action/releases)
- [Changelog](https://github.com/lewagon/wait-on-check-action/blob/master/CHANGELOG.md)
- [Commits](lewagon/wait-on-check-action@ccfb013...7404930)

---
updated-dependencies:
- dependency-name: lewagon/wait-on-check-action
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 22, 2026
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner March 22, 2026 11:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 22, 2026
@hyperpolymath
hyperpolymath enabled auto-merge (rebase) March 22, 2026 11:26
@hyperpolymath
hyperpolymath merged commit 645e9e6 into main Mar 22, 2026
16 of 22 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/lewagon/wait-on-check-action-1.5.0 branch March 22, 2026 11:26
Repository owner deleted a comment from chatgpt-codex-connector Bot May 13, 2026
hyperpolymath added a commit that referenced this pull request Sep 22, 2026
…estate-wide startup_failure) (#828)

## Summary

Estate-wide incident: `github/codeql-action` **v4.38.1** fails GitHub
workflow **startup** on every repo that took it — CodeQL/Hypatia runs
die with `startup_failure`, zero jobs dispatched, no error text in any
API surface. The evidence chain (full detail: **nexia-list#100**):

| repo | ref | status |
|---|---|---|
| nexia-list | `@v4.38.1` tag (via dependabot #94) | 🔴 startup_failure →
fixed by rollback #100 (merged) |
| hypatia | `@1c5b675` (4.38.1 SHA) | 🔴 |
| vexometer | `@v4.38.1` | 🔴 (since Sep-21) |
| rsr-template-repo | `@1c5b675` | 🔴 |
| affinescript / boj-server / deed-ecosystem | ≤ v4.38.0 | ✅ green |

The v4.38.1 tag *exists* (peels to `1c5b675`) and byte-identical
workflow content runs under a fresh path — so the failure is the
**version value itself** at GitHub's start-validation layer, not
content, permissions (probes with `security-events` start fine), or the
default-setup conflict.

## Changes here

- `codeql-reusable.yml`, `hypatia-scan-reusable.yml`: `codeql-action/*`
re-pinned `1c5b675` (v4.38.1) → `b96794f0` (**v4.38.0** commit; wrong `#
v3` comments corrected to `# v4.38.0`).
- `actions.lock`: re-keyed to the v4.38.0 SHA entries (dependabot bumped
the reusable pins without regenerating the lock).
- `dependabot.yml`: **full hold** on `github/codeql-action` — scoped
`versions:` ignores do NOT hold for this bot path (nexia-list#101
re-raised the bump in SHA form within an hour, copying the inline
warning comment verbatim while swapping the SHA).

## Follow-ups

Consumer rollbacks shipped in the same batch: nexia-list (merged ✅),
**hypatia**, **vexometer**, **rsr-template-repo**,
**metadatastician/burble** (each with the same dependabot hold).
Reconsider the hold when upstream clears v4.38.1 or a newer release
verifies green on one canary repo.

Co-authored-by: arena-agent <arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant