Align dependabot, merge-bot, release flow, and SHA-pin all actions - #692

Merged
ptr727 merged 6 commits into
developfrom
pull-project-alignment
May 7, 2026
Merged

Align dependabot, merge-bot, release flow, and SHA-pin all actions#692
ptr727 merged 6 commits into
developfrom
pull-project-alignment

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Brings PlexCleaner in line with the dual-publish "pull project" pattern adopted by ptr727/ProjectTemplate and ptr727/homeassistant-purpleair.

  • dependabot.yml: also targets develop so both auto-publishing branches stay in sync.
  • merge-bot-pull-request.yml: branch-aware merge method (squash for develop, merge for main) + App-token auth so post-merge pushes trigger publish workflows on develop instead of being skipped by GitHub's recursion guard.
  • build-release-task.yml: target_commitish=github.sha so release tags land on the triggering commit (not main's tip when triggered from develop) + fail_on_unmatched_files.
  • All workflows: every third-party action pinned to a commit SHA with # vX.Y.Z comment; dotnet/nbgv@master replaced with @v0.5.1.
  • AGENTS.md + copilot-instructions.md: document branch flow, merge strategy split, dual-publish release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.

Branch rulesets and repo merge settings have already been updated via gh api to match (rebase disabled, auto-merge enabled, develop = squash-only + linear history, main = merge-only, both with Check pull request workflow status as the required check).

Test plan

  • CI green (test-pull-request workflow)
  • Copilot review threads resolved (required by ruleset)
  • Squash-merge into develop (only method allowed by new develop ruleset) → triggers publish-release.yml and produces a develop prerelease
  • Confirm release tag points at the develop commit SHA (verifies target_commitish fix)

🤖 Generated with Claude Code

ptr727and others added 3 commits May 7, 2026 12:51
- dependabot.yml: also target develop so both auto-publishing branches
stay on the same baseline.
- merge-bot-pull-request.yml: branch-aware merge method (squash for
develop, merge for main) and App-token auth so post-merge pushes
trigger publish-release and publish-periodic-docker-release on
develop instead of being skipped by GitHub's recursion guard.
- build-release-task.yml: set target_commitish=github.sha so release
tags land on the triggering commit, not the repo default branch;
fail_on_unmatched_files; pin softprops/action-gh-release to v3.0.0.
- AGENTS.md: document the feature->develop->main flow, develop->main
promotion via merge commit, dual-publish release flow, dependabot
rationale, and merge-bot design.
- copilot-instructions.md: terse summary section pointing at AGENTS.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace floating major-version refs (@v5/@v6/@v7/@v8/@v3/@v4/@v1) and
the @master ref on dotnet/nbgv with full commit SHAs plus version
comments, matching the pattern already used for create-github-app-token,
fetch-metadata, and softprops/action-gh-release. Pins make supply-chain
attacks via tag mutation impossible and let dependabot bump them
mechanically.
Also drops the verbose target_commitish rationale comment from
build-release-task.yml; the field is self-explanatory in this repo's
context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The previous commit pinned every third-party action to a commit SHA but
didn't capture the rule itself. Add a "GitHub Actions pinning" section
to AGENTS.md explaining what to pin, why floating tags are unsafe, and
how to resolve a SHA when adding a new action. Add a one-line summary
to copilot-instructions.md so AI agents don't reintroduce floating
refs in suggestions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings May 7, 2026 20:06

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates PlexCleaner’s automation to match a dual-branch (develop/main) “pull project” release model, with bot-driven dependency maintenance and hardened GitHub Actions usage (SHA-pinning).

Changes:

  • Extend Dependabot to target both main and develop, and update merge-bot behavior to be branch-aware (squash to develop, merge-commit to main) using an App token.
  • Fix release tagging behavior by setting target_commitish: ${{ github.sha }} and tighten release asset upload behavior with fail_on_unmatched_files.
  • Pin third-party GitHub Actions to immutable commit SHAs across workflows and document the branch/release/bot policies.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
AGENTS.mdDocuments branch flow, release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.
.github/copilot-instructions.mdAdds concise guidance for agents on branching/release strategy and action pinning.
.github/dependabot.ymlAdds parallel Dependabot update configs for develop in addition to main.
.github/workflows/merge-bot-pull-request.ymlUses App token and selects merge method based on base branch rules.
.github/workflows/build-release-task.ymlPins actions; ensures release tags target the triggering commit and fails on missing assets.
.github/workflows/get-version-task.ymlPins actions and replaces floating dotnet/nbgv@master with a versioned SHA pin.
.github/workflows/build-executable-task.ymlPins setup-dotnet/checkout/artifact actions.
.github/workflows/build-docker-task.ymlPins docker setup/login/build actions.
.github/workflows/publish-periodic-docker-release.ymlPins actions for docker-run, artifacts, checkout, download-artifact, and dockerhub description.
.github/workflows/build-datebadge-task.ymlPins BYOB action to a commit SHA.
.github/workflows/test-release-task.ymlPins setup-dotnet and checkout actions.

Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Every other workflow file in the repo uses the over-indented YAML style
where list items under `steps:` are at parent_indent+2 (e.g., `steps:`
at column 4, `- name:` at column 6). This file alone used the compact
style with both at the same column. Both are valid YAML and GitHub
Actions accepts either, but consistency matters more than syntactic
flexibility. Bring this file in line with the other six.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/merge-bot-pull-request.yml
Comment thread.github/workflows/publish-periodic-docker-release.yml
Two clarifications surfaced by Copilot review on PR #692:
1. The merge-bot uses an App token minted from CODEGEN_APP_*
secrets. For Dependabot-authored pull_request events, GitHub only
exposes secrets from the Dependabot namespace (Settings → Secrets
→ Dependabot), not the regular Actions namespace. The secrets must
exist in both, or the App-token step gets empty inputs at runtime.
This is non-obvious and worth calling out explicitly so future
maintainers don't strip the Dependabot duplicate as redundant.
2. The SHA-pinning comment convention is "match the upstream release
tag" — usually # vX.Y.Z, but # v3 (or # master) when upstream only
publishes major-only / branch tags. Don't fabricate a semver
suffix; use what gh api repos/<owner>/<repo>/releases/latest
returns as tag_name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit 478e0a7 into developMay 7, 2026
16 checks passed
@ptr727
ptr727 deleted the pull-project-alignment branch May 7, 2026 20:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Align dependabot, merge-bot, release flow, and SHA-pin all actions - #692

Merged
ptr727 merged 6 commits into
developfrom
pull-project-alignment
May 7, 2026
Merged

Align dependabot, merge-bot, release flow, and SHA-pin all actions#692
ptr727 merged 6 commits into
developfrom
pull-project-alignment

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Brings PlexCleaner in line with the dual-publish "pull project" pattern adopted by ptr727/ProjectTemplate and ptr727/homeassistant-purpleair.

  • dependabot.yml: also targets develop so both auto-publishing branches stay in sync.
  • merge-bot-pull-request.yml: branch-aware merge method (squash for develop, merge for main) + App-token auth so post-merge pushes trigger publish workflows on develop instead of being skipped by GitHub's recursion guard.
  • build-release-task.yml: target_commitish=github.sha so release tags land on the triggering commit (not main's tip when triggered from develop) + fail_on_unmatched_files.
  • All workflows: every third-party action pinned to a commit SHA with # vX.Y.Z comment; dotnet/nbgv@master replaced with @v0.5.1.
  • AGENTS.md + copilot-instructions.md: document branch flow, merge strategy split, dual-publish release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.

Branch rulesets and repo merge settings have already been updated via gh api to match (rebase disabled, auto-merge enabled, develop = squash-only + linear history, main = merge-only, both with Check pull request workflow status as the required check).

Test plan

  • CI green (test-pull-request workflow)
  • Copilot review threads resolved (required by ruleset)
  • Squash-merge into develop (only method allowed by new develop ruleset) → triggers publish-release.yml and produces a develop prerelease
  • Confirm release tag points at the develop commit SHA (verifies target_commitish fix)

🤖 Generated with Claude Code

ptr727and others added 3 commits May 7, 2026 12:51
- dependabot.yml: also target develop so both auto-publishing branches
stay on the same baseline.
- merge-bot-pull-request.yml: branch-aware merge method (squash for
develop, merge for main) and App-token auth so post-merge pushes
trigger publish-release and publish-periodic-docker-release on
develop instead of being skipped by GitHub's recursion guard.
- build-release-task.yml: set target_commitish=github.sha so release
tags land on the triggering commit, not the repo default branch;
fail_on_unmatched_files; pin softprops/action-gh-release to v3.0.0.
- AGENTS.md: document the feature->develop->main flow, develop->main
promotion via merge commit, dual-publish release flow, dependabot
rationale, and merge-bot design.
- copilot-instructions.md: terse summary section pointing at AGENTS.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace floating major-version refs (@v5/@v6/@v7/@v8/@v3/@v4/@v1) and
the @master ref on dotnet/nbgv with full commit SHAs plus version
comments, matching the pattern already used for create-github-app-token,
fetch-metadata, and softprops/action-gh-release. Pins make supply-chain
attacks via tag mutation impossible and let dependabot bump them
mechanically.
Also drops the verbose target_commitish rationale comment from
build-release-task.yml; the field is self-explanatory in this repo's
context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The previous commit pinned every third-party action to a commit SHA but
didn't capture the rule itself. Add a "GitHub Actions pinning" section
to AGENTS.md explaining what to pin, why floating tags are unsafe, and
how to resolve a SHA when adding a new action. Add a one-line summary
to copilot-instructions.md so AI agents don't reintroduce floating
refs in suggestions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings May 7, 2026 20:06

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates PlexCleaner’s automation to match a dual-branch (develop/main) “pull project” release model, with bot-driven dependency maintenance and hardened GitHub Actions usage (SHA-pinning).

Changes:

  • Extend Dependabot to target both main and develop, and update merge-bot behavior to be branch-aware (squash to develop, merge-commit to main) using an App token.
  • Fix release tagging behavior by setting target_commitish: ${{ github.sha }} and tighten release asset upload behavior with fail_on_unmatched_files.
  • Pin third-party GitHub Actions to immutable commit SHAs across workflows and document the branch/release/bot policies.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
AGENTS.mdDocuments branch flow, release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.
.github/copilot-instructions.mdAdds concise guidance for agents on branching/release strategy and action pinning.
.github/dependabot.ymlAdds parallel Dependabot update configs for develop in addition to main.
.github/workflows/merge-bot-pull-request.ymlUses App token and selects merge method based on base branch rules.
.github/workflows/build-release-task.ymlPins actions; ensures release tags target the triggering commit and fails on missing assets.
.github/workflows/get-version-task.ymlPins actions and replaces floating dotnet/nbgv@master with a versioned SHA pin.
.github/workflows/build-executable-task.ymlPins setup-dotnet/checkout/artifact actions.
.github/workflows/build-docker-task.ymlPins docker setup/login/build actions.
.github/workflows/publish-periodic-docker-release.ymlPins actions for docker-run, artifacts, checkout, download-artifact, and dockerhub description.
.github/workflows/build-datebadge-task.ymlPins BYOB action to a commit SHA.
.github/workflows/test-release-task.ymlPins setup-dotnet and checkout actions.

Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Every other workflow file in the repo uses the over-indented YAML style
where list items under `steps:` are at parent_indent+2 (e.g., `steps:`
at column 4, `- name:` at column 6). This file alone used the compact
style with both at the same column. Both are valid YAML and GitHub
Actions accepts either, but consistency matters more than syntactic
flexibility. Bring this file in line with the other six.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/merge-bot-pull-request.yml
Comment thread.github/workflows/publish-periodic-docker-release.yml
Two clarifications surfaced by Copilot review on PR #692:
1. The merge-bot uses an App token minted from CODEGEN_APP_*
secrets. For Dependabot-authored pull_request events, GitHub only
exposes secrets from the Dependabot namespace (Settings → Secrets
→ Dependabot), not the regular Actions namespace. The secrets must
exist in both, or the App-token step gets empty inputs at runtime.
This is non-obvious and worth calling out explicitly so future
maintainers don't strip the Dependabot duplicate as redundant.
2. The SHA-pinning comment convention is "match the upstream release
tag" — usually # vX.Y.Z, but # v3 (or # master) when upstream only
publishes major-only / branch tags. Don't fabricate a semver
suffix; use what gh api repos/<owner>/<repo>/releases/latest
returns as tag_name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit 478e0a7 into developMay 7, 2026
16 checks passed
@ptr727
ptr727 deleted the pull-project-alignment branch May 7, 2026 20:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Align dependabot, merge-bot, release flow, and SHA-pin all actions - #692

Merged
ptr727 merged 6 commits into
developfrom
pull-project-alignment
May 7, 2026
Merged

Align dependabot, merge-bot, release flow, and SHA-pin all actions#692
ptr727 merged 6 commits into
developfrom
pull-project-alignment

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Brings PlexCleaner in line with the dual-publish "pull project" pattern adopted by ptr727/ProjectTemplate and ptr727/homeassistant-purpleair.

  • dependabot.yml: also targets develop so both auto-publishing branches stay in sync.
  • merge-bot-pull-request.yml: branch-aware merge method (squash for develop, merge for main) + App-token auth so post-merge pushes trigger publish workflows on develop instead of being skipped by GitHub's recursion guard.
  • build-release-task.yml: target_commitish=github.sha so release tags land on the triggering commit (not main's tip when triggered from develop) + fail_on_unmatched_files.
  • All workflows: every third-party action pinned to a commit SHA with # vX.Y.Z comment; dotnet/nbgv@master replaced with @v0.5.1.
  • AGENTS.md + copilot-instructions.md: document branch flow, merge strategy split, dual-publish release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.

Branch rulesets and repo merge settings have already been updated via gh api to match (rebase disabled, auto-merge enabled, develop = squash-only + linear history, main = merge-only, both with Check pull request workflow status as the required check).

Test plan

  • CI green (test-pull-request workflow)
  • Copilot review threads resolved (required by ruleset)
  • Squash-merge into develop (only method allowed by new develop ruleset) → triggers publish-release.yml and produces a develop prerelease
  • Confirm release tag points at the develop commit SHA (verifies target_commitish fix)

🤖 Generated with Claude Code

ptr727and others added 3 commits May 7, 2026 12:51
- dependabot.yml: also target develop so both auto-publishing branches
stay on the same baseline.
- merge-bot-pull-request.yml: branch-aware merge method (squash for
develop, merge for main) and App-token auth so post-merge pushes
trigger publish-release and publish-periodic-docker-release on
develop instead of being skipped by GitHub's recursion guard.
- build-release-task.yml: set target_commitish=github.sha so release
tags land on the triggering commit, not the repo default branch;
fail_on_unmatched_files; pin softprops/action-gh-release to v3.0.0.
- AGENTS.md: document the feature->develop->main flow, develop->main
promotion via merge commit, dual-publish release flow, dependabot
rationale, and merge-bot design.
- copilot-instructions.md: terse summary section pointing at AGENTS.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace floating major-version refs (@v5/@v6/@v7/@v8/@v3/@v4/@v1) and
the @master ref on dotnet/nbgv with full commit SHAs plus version
comments, matching the pattern already used for create-github-app-token,
fetch-metadata, and softprops/action-gh-release. Pins make supply-chain
attacks via tag mutation impossible and let dependabot bump them
mechanically.
Also drops the verbose target_commitish rationale comment from
build-release-task.yml; the field is self-explanatory in this repo's
context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The previous commit pinned every third-party action to a commit SHA but
didn't capture the rule itself. Add a "GitHub Actions pinning" section
to AGENTS.md explaining what to pin, why floating tags are unsafe, and
how to resolve a SHA when adding a new action. Add a one-line summary
to copilot-instructions.md so AI agents don't reintroduce floating
refs in suggestions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings May 7, 2026 20:06

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates PlexCleaner’s automation to match a dual-branch (develop/main) “pull project” release model, with bot-driven dependency maintenance and hardened GitHub Actions usage (SHA-pinning).

Changes:

  • Extend Dependabot to target both main and develop, and update merge-bot behavior to be branch-aware (squash to develop, merge-commit to main) using an App token.
  • Fix release tagging behavior by setting target_commitish: ${{ github.sha }} and tighten release asset upload behavior with fail_on_unmatched_files.
  • Pin third-party GitHub Actions to immutable commit SHAs across workflows and document the branch/release/bot policies.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
AGENTS.mdDocuments branch flow, release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.
.github/copilot-instructions.mdAdds concise guidance for agents on branching/release strategy and action pinning.
.github/dependabot.ymlAdds parallel Dependabot update configs for develop in addition to main.
.github/workflows/merge-bot-pull-request.ymlUses App token and selects merge method based on base branch rules.
.github/workflows/build-release-task.ymlPins actions; ensures release tags target the triggering commit and fails on missing assets.
.github/workflows/get-version-task.ymlPins actions and replaces floating dotnet/nbgv@master with a versioned SHA pin.
.github/workflows/build-executable-task.ymlPins setup-dotnet/checkout/artifact actions.
.github/workflows/build-docker-task.ymlPins docker setup/login/build actions.
.github/workflows/publish-periodic-docker-release.ymlPins actions for docker-run, artifacts, checkout, download-artifact, and dockerhub description.
.github/workflows/build-datebadge-task.ymlPins BYOB action to a commit SHA.
.github/workflows/test-release-task.ymlPins setup-dotnet and checkout actions.

Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Every other workflow file in the repo uses the over-indented YAML style
where list items under `steps:` are at parent_indent+2 (e.g., `steps:`
at column 4, `- name:` at column 6). This file alone used the compact
style with both at the same column. Both are valid YAML and GitHub
Actions accepts either, but consistency matters more than syntactic
flexibility. Bring this file in line with the other six.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/merge-bot-pull-request.yml
Comment thread.github/workflows/publish-periodic-docker-release.yml
Two clarifications surfaced by Copilot review on PR #692:
1. The merge-bot uses an App token minted from CODEGEN_APP_*
secrets. For Dependabot-authored pull_request events, GitHub only
exposes secrets from the Dependabot namespace (Settings → Secrets
→ Dependabot), not the regular Actions namespace. The secrets must
exist in both, or the App-token step gets empty inputs at runtime.
This is non-obvious and worth calling out explicitly so future
maintainers don't strip the Dependabot duplicate as redundant.
2. The SHA-pinning comment convention is "match the upstream release
tag" — usually # vX.Y.Z, but # v3 (or # master) when upstream only
publishes major-only / branch tags. Don't fabricate a semver
suffix; use what gh api repos/<owner>/<repo>/releases/latest
returns as tag_name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit 478e0a7 into developMay 7, 2026
16 checks passed
@ptr727
ptr727 deleted the pull-project-alignment branch May 7, 2026 20:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Align dependabot, merge-bot, release flow, and SHA-pin all actions - #692

Merged
ptr727 merged 6 commits into
developfrom
pull-project-alignment
May 7, 2026
Merged

Align dependabot, merge-bot, release flow, and SHA-pin all actions#692
ptr727 merged 6 commits into
developfrom
pull-project-alignment

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Brings PlexCleaner in line with the dual-publish "pull project" pattern adopted by ptr727/ProjectTemplate and ptr727/homeassistant-purpleair.

  • dependabot.yml: also targets develop so both auto-publishing branches stay in sync.
  • merge-bot-pull-request.yml: branch-aware merge method (squash for develop, merge for main) + App-token auth so post-merge pushes trigger publish workflows on develop instead of being skipped by GitHub's recursion guard.
  • build-release-task.yml: target_commitish=github.sha so release tags land on the triggering commit (not main's tip when triggered from develop) + fail_on_unmatched_files.
  • All workflows: every third-party action pinned to a commit SHA with # vX.Y.Z comment; dotnet/nbgv@master replaced with @v0.5.1.
  • AGENTS.md + copilot-instructions.md: document branch flow, merge strategy split, dual-publish release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.

Branch rulesets and repo merge settings have already been updated via gh api to match (rebase disabled, auto-merge enabled, develop = squash-only + linear history, main = merge-only, both with Check pull request workflow status as the required check).

Test plan

  • CI green (test-pull-request workflow)
  • Copilot review threads resolved (required by ruleset)
  • Squash-merge into develop (only method allowed by new develop ruleset) → triggers publish-release.yml and produces a develop prerelease
  • Confirm release tag points at the develop commit SHA (verifies target_commitish fix)

🤖 Generated with Claude Code

ptr727and others added 3 commits May 7, 2026 12:51
- dependabot.yml: also target develop so both auto-publishing branches
stay on the same baseline.
- merge-bot-pull-request.yml: branch-aware merge method (squash for
develop, merge for main) and App-token auth so post-merge pushes
trigger publish-release and publish-periodic-docker-release on
develop instead of being skipped by GitHub's recursion guard.
- build-release-task.yml: set target_commitish=github.sha so release
tags land on the triggering commit, not the repo default branch;
fail_on_unmatched_files; pin softprops/action-gh-release to v3.0.0.
- AGENTS.md: document the feature->develop->main flow, develop->main
promotion via merge commit, dual-publish release flow, dependabot
rationale, and merge-bot design.
- copilot-instructions.md: terse summary section pointing at AGENTS.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace floating major-version refs (@v5/@v6/@v7/@v8/@v3/@v4/@v1) and
the @master ref on dotnet/nbgv with full commit SHAs plus version
comments, matching the pattern already used for create-github-app-token,
fetch-metadata, and softprops/action-gh-release. Pins make supply-chain
attacks via tag mutation impossible and let dependabot bump them
mechanically.
Also drops the verbose target_commitish rationale comment from
build-release-task.yml; the field is self-explanatory in this repo's
context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The previous commit pinned every third-party action to a commit SHA but
didn't capture the rule itself. Add a "GitHub Actions pinning" section
to AGENTS.md explaining what to pin, why floating tags are unsafe, and
how to resolve a SHA when adding a new action. Add a one-line summary
to copilot-instructions.md so AI agents don't reintroduce floating
refs in suggestions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings May 7, 2026 20:06

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates PlexCleaner’s automation to match a dual-branch (develop/main) “pull project” release model, with bot-driven dependency maintenance and hardened GitHub Actions usage (SHA-pinning).

Changes:

  • Extend Dependabot to target both main and develop, and update merge-bot behavior to be branch-aware (squash to develop, merge-commit to main) using an App token.
  • Fix release tagging behavior by setting target_commitish: ${{ github.sha }} and tighten release asset upload behavior with fail_on_unmatched_files.
  • Pin third-party GitHub Actions to immutable commit SHAs across workflows and document the branch/release/bot policies.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
AGENTS.mdDocuments branch flow, release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.
.github/copilot-instructions.mdAdds concise guidance for agents on branching/release strategy and action pinning.
.github/dependabot.ymlAdds parallel Dependabot update configs for develop in addition to main.
.github/workflows/merge-bot-pull-request.ymlUses App token and selects merge method based on base branch rules.
.github/workflows/build-release-task.ymlPins actions; ensures release tags target the triggering commit and fails on missing assets.
.github/workflows/get-version-task.ymlPins actions and replaces floating dotnet/nbgv@master with a versioned SHA pin.
.github/workflows/build-executable-task.ymlPins setup-dotnet/checkout/artifact actions.
.github/workflows/build-docker-task.ymlPins docker setup/login/build actions.
.github/workflows/publish-periodic-docker-release.ymlPins actions for docker-run, artifacts, checkout, download-artifact, and dockerhub description.
.github/workflows/build-datebadge-task.ymlPins BYOB action to a commit SHA.
.github/workflows/test-release-task.ymlPins setup-dotnet and checkout actions.

Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Every other workflow file in the repo uses the over-indented YAML style
where list items under `steps:` are at parent_indent+2 (e.g., `steps:`
at column 4, `- name:` at column 6). This file alone used the compact
style with both at the same column. Both are valid YAML and GitHub
Actions accepts either, but consistency matters more than syntactic
flexibility. Bring this file in line with the other six.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/merge-bot-pull-request.yml
Comment thread.github/workflows/publish-periodic-docker-release.yml
Two clarifications surfaced by Copilot review on PR #692:
1. The merge-bot uses an App token minted from CODEGEN_APP_*
secrets. For Dependabot-authored pull_request events, GitHub only
exposes secrets from the Dependabot namespace (Settings → Secrets
→ Dependabot), not the regular Actions namespace. The secrets must
exist in both, or the App-token step gets empty inputs at runtime.
This is non-obvious and worth calling out explicitly so future
maintainers don't strip the Dependabot duplicate as redundant.
2. The SHA-pinning comment convention is "match the upstream release
tag" — usually # vX.Y.Z, but # v3 (or # master) when upstream only
publishes major-only / branch tags. Don't fabricate a semver
suffix; use what gh api repos/<owner>/<repo>/releases/latest
returns as tag_name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit 478e0a7 into developMay 7, 2026
16 checks passed
@ptr727
ptr727 deleted the pull-project-alignment branch May 7, 2026 20:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Align dependabot, merge-bot, release flow, and SHA-pin all actions - #692

Merged
ptr727 merged 6 commits into
developfrom
pull-project-alignment
May 7, 2026
Merged

Align dependabot, merge-bot, release flow, and SHA-pin all actions#692
ptr727 merged 6 commits into
developfrom
pull-project-alignment

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Brings PlexCleaner in line with the dual-publish "pull project" pattern adopted by ptr727/ProjectTemplate and ptr727/homeassistant-purpleair.

  • dependabot.yml: also targets develop so both auto-publishing branches stay in sync.
  • merge-bot-pull-request.yml: branch-aware merge method (squash for develop, merge for main) + App-token auth so post-merge pushes trigger publish workflows on develop instead of being skipped by GitHub's recursion guard.
  • build-release-task.yml: target_commitish=github.sha so release tags land on the triggering commit (not main's tip when triggered from develop) + fail_on_unmatched_files.
  • All workflows: every third-party action pinned to a commit SHA with # vX.Y.Z comment; dotnet/nbgv@master replaced with @v0.5.1.
  • AGENTS.md + copilot-instructions.md: document branch flow, merge strategy split, dual-publish release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.

Branch rulesets and repo merge settings have already been updated via gh api to match (rebase disabled, auto-merge enabled, develop = squash-only + linear history, main = merge-only, both with Check pull request workflow status as the required check).

Test plan

  • CI green (test-pull-request workflow)
  • Copilot review threads resolved (required by ruleset)
  • Squash-merge into develop (only method allowed by new develop ruleset) → triggers publish-release.yml and produces a develop prerelease
  • Confirm release tag points at the develop commit SHA (verifies target_commitish fix)

🤖 Generated with Claude Code

ptr727and others added 3 commits May 7, 2026 12:51
- dependabot.yml: also target develop so both auto-publishing branches
stay on the same baseline.
- merge-bot-pull-request.yml: branch-aware merge method (squash for
develop, merge for main) and App-token auth so post-merge pushes
trigger publish-release and publish-periodic-docker-release on
develop instead of being skipped by GitHub's recursion guard.
- build-release-task.yml: set target_commitish=github.sha so release
tags land on the triggering commit, not the repo default branch;
fail_on_unmatched_files; pin softprops/action-gh-release to v3.0.0.
- AGENTS.md: document the feature->develop->main flow, develop->main
promotion via merge commit, dual-publish release flow, dependabot
rationale, and merge-bot design.
- copilot-instructions.md: terse summary section pointing at AGENTS.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace floating major-version refs (@v5/@v6/@v7/@v8/@v3/@v4/@v1) and
the @master ref on dotnet/nbgv with full commit SHAs plus version
comments, matching the pattern already used for create-github-app-token,
fetch-metadata, and softprops/action-gh-release. Pins make supply-chain
attacks via tag mutation impossible and let dependabot bump them
mechanically.
Also drops the verbose target_commitish rationale comment from
build-release-task.yml; the field is self-explanatory in this repo's
context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The previous commit pinned every third-party action to a commit SHA but
didn't capture the rule itself. Add a "GitHub Actions pinning" section
to AGENTS.md explaining what to pin, why floating tags are unsafe, and
how to resolve a SHA when adding a new action. Add a one-line summary
to copilot-instructions.md so AI agents don't reintroduce floating
refs in suggestions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings May 7, 2026 20:06

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates PlexCleaner’s automation to match a dual-branch (develop/main) “pull project” release model, with bot-driven dependency maintenance and hardened GitHub Actions usage (SHA-pinning).

Changes:

  • Extend Dependabot to target both main and develop, and update merge-bot behavior to be branch-aware (squash to develop, merge-commit to main) using an App token.
  • Fix release tagging behavior by setting target_commitish: ${{ github.sha }} and tighten release asset upload behavior with fail_on_unmatched_files.
  • Pin third-party GitHub Actions to immutable commit SHAs across workflows and document the branch/release/bot policies.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
AGENTS.mdDocuments branch flow, release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.
.github/copilot-instructions.mdAdds concise guidance for agents on branching/release strategy and action pinning.
.github/dependabot.ymlAdds parallel Dependabot update configs for develop in addition to main.
.github/workflows/merge-bot-pull-request.ymlUses App token and selects merge method based on base branch rules.
.github/workflows/build-release-task.ymlPins actions; ensures release tags target the triggering commit and fails on missing assets.
.github/workflows/get-version-task.ymlPins actions and replaces floating dotnet/nbgv@master with a versioned SHA pin.
.github/workflows/build-executable-task.ymlPins setup-dotnet/checkout/artifact actions.
.github/workflows/build-docker-task.ymlPins docker setup/login/build actions.
.github/workflows/publish-periodic-docker-release.ymlPins actions for docker-run, artifacts, checkout, download-artifact, and dockerhub description.
.github/workflows/build-datebadge-task.ymlPins BYOB action to a commit SHA.
.github/workflows/test-release-task.ymlPins setup-dotnet and checkout actions.

Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Every other workflow file in the repo uses the over-indented YAML style
where list items under `steps:` are at parent_indent+2 (e.g., `steps:`
at column 4, `- name:` at column 6). This file alone used the compact
style with both at the same column. Both are valid YAML and GitHub
Actions accepts either, but consistency matters more than syntactic
flexibility. Bring this file in line with the other six.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/merge-bot-pull-request.yml
Comment thread.github/workflows/publish-periodic-docker-release.yml
Two clarifications surfaced by Copilot review on PR #692:
1. The merge-bot uses an App token minted from CODEGEN_APP_*
secrets. For Dependabot-authored pull_request events, GitHub only
exposes secrets from the Dependabot namespace (Settings → Secrets
→ Dependabot), not the regular Actions namespace. The secrets must
exist in both, or the App-token step gets empty inputs at runtime.
This is non-obvious and worth calling out explicitly so future
maintainers don't strip the Dependabot duplicate as redundant.
2. The SHA-pinning comment convention is "match the upstream release
tag" — usually # vX.Y.Z, but # v3 (or # master) when upstream only
publishes major-only / branch tags. Don't fabricate a semver
suffix; use what gh api repos/<owner>/<repo>/releases/latest
returns as tag_name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit 478e0a7 into developMay 7, 2026
16 checks passed
@ptr727
ptr727 deleted the pull-project-alignment branch May 7, 2026 20:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Align dependabot, merge-bot, release flow, and SHA-pin all actions - #692

Merged
ptr727 merged 6 commits into
developfrom
pull-project-alignment
May 7, 2026
Merged

Align dependabot, merge-bot, release flow, and SHA-pin all actions#692
ptr727 merged 6 commits into
developfrom
pull-project-alignment

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Brings PlexCleaner in line with the dual-publish "pull project" pattern adopted by ptr727/ProjectTemplate and ptr727/homeassistant-purpleair.

  • dependabot.yml: also targets develop so both auto-publishing branches stay in sync.
  • merge-bot-pull-request.yml: branch-aware merge method (squash for develop, merge for main) + App-token auth so post-merge pushes trigger publish workflows on develop instead of being skipped by GitHub's recursion guard.
  • build-release-task.yml: target_commitish=github.sha so release tags land on the triggering commit (not main's tip when triggered from develop) + fail_on_unmatched_files.
  • All workflows: every third-party action pinned to a commit SHA with # vX.Y.Z comment; dotnet/nbgv@master replaced with @v0.5.1.
  • AGENTS.md + copilot-instructions.md: document branch flow, merge strategy split, dual-publish release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.

Branch rulesets and repo merge settings have already been updated via gh api to match (rebase disabled, auto-merge enabled, develop = squash-only + linear history, main = merge-only, both with Check pull request workflow status as the required check).

Test plan

  • CI green (test-pull-request workflow)
  • Copilot review threads resolved (required by ruleset)
  • Squash-merge into develop (only method allowed by new develop ruleset) → triggers publish-release.yml and produces a develop prerelease
  • Confirm release tag points at the develop commit SHA (verifies target_commitish fix)

🤖 Generated with Claude Code

ptr727and others added 3 commits May 7, 2026 12:51
- dependabot.yml: also target develop so both auto-publishing branches
stay on the same baseline.
- merge-bot-pull-request.yml: branch-aware merge method (squash for
develop, merge for main) and App-token auth so post-merge pushes
trigger publish-release and publish-periodic-docker-release on
develop instead of being skipped by GitHub's recursion guard.
- build-release-task.yml: set target_commitish=github.sha so release
tags land on the triggering commit, not the repo default branch;
fail_on_unmatched_files; pin softprops/action-gh-release to v3.0.0.
- AGENTS.md: document the feature->develop->main flow, develop->main
promotion via merge commit, dual-publish release flow, dependabot
rationale, and merge-bot design.
- copilot-instructions.md: terse summary section pointing at AGENTS.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace floating major-version refs (@v5/@v6/@v7/@v8/@v3/@v4/@v1) and
the @master ref on dotnet/nbgv with full commit SHAs plus version
comments, matching the pattern already used for create-github-app-token,
fetch-metadata, and softprops/action-gh-release. Pins make supply-chain
attacks via tag mutation impossible and let dependabot bump them
mechanically.
Also drops the verbose target_commitish rationale comment from
build-release-task.yml; the field is self-explanatory in this repo's
context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The previous commit pinned every third-party action to a commit SHA but
didn't capture the rule itself. Add a "GitHub Actions pinning" section
to AGENTS.md explaining what to pin, why floating tags are unsafe, and
how to resolve a SHA when adding a new action. Add a one-line summary
to copilot-instructions.md so AI agents don't reintroduce floating
refs in suggestions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings May 7, 2026 20:06

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates PlexCleaner’s automation to match a dual-branch (develop/main) “pull project” release model, with bot-driven dependency maintenance and hardened GitHub Actions usage (SHA-pinning).

Changes:

  • Extend Dependabot to target both main and develop, and update merge-bot behavior to be branch-aware (squash to develop, merge-commit to main) using an App token.
  • Fix release tagging behavior by setting target_commitish: ${{ github.sha }} and tighten release asset upload behavior with fail_on_unmatched_files.
  • Pin third-party GitHub Actions to immutable commit SHAs across workflows and document the branch/release/bot policies.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
AGENTS.mdDocuments branch flow, release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.
.github/copilot-instructions.mdAdds concise guidance for agents on branching/release strategy and action pinning.
.github/dependabot.ymlAdds parallel Dependabot update configs for develop in addition to main.
.github/workflows/merge-bot-pull-request.ymlUses App token and selects merge method based on base branch rules.
.github/workflows/build-release-task.ymlPins actions; ensures release tags target the triggering commit and fails on missing assets.
.github/workflows/get-version-task.ymlPins actions and replaces floating dotnet/nbgv@master with a versioned SHA pin.
.github/workflows/build-executable-task.ymlPins setup-dotnet/checkout/artifact actions.
.github/workflows/build-docker-task.ymlPins docker setup/login/build actions.
.github/workflows/publish-periodic-docker-release.ymlPins actions for docker-run, artifacts, checkout, download-artifact, and dockerhub description.
.github/workflows/build-datebadge-task.ymlPins BYOB action to a commit SHA.
.github/workflows/test-release-task.ymlPins setup-dotnet and checkout actions.

Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Every other workflow file in the repo uses the over-indented YAML style
where list items under `steps:` are at parent_indent+2 (e.g., `steps:`
at column 4, `- name:` at column 6). This file alone used the compact
style with both at the same column. Both are valid YAML and GitHub
Actions accepts either, but consistency matters more than syntactic
flexibility. Bring this file in line with the other six.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/merge-bot-pull-request.yml
Comment thread.github/workflows/publish-periodic-docker-release.yml
Two clarifications surfaced by Copilot review on PR #692:
1. The merge-bot uses an App token minted from CODEGEN_APP_*
secrets. For Dependabot-authored pull_request events, GitHub only
exposes secrets from the Dependabot namespace (Settings → Secrets
→ Dependabot), not the regular Actions namespace. The secrets must
exist in both, or the App-token step gets empty inputs at runtime.
This is non-obvious and worth calling out explicitly so future
maintainers don't strip the Dependabot duplicate as redundant.
2. The SHA-pinning comment convention is "match the upstream release
tag" — usually # vX.Y.Z, but # v3 (or # master) when upstream only
publishes major-only / branch tags. Don't fabricate a semver
suffix; use what gh api repos/<owner>/<repo>/releases/latest
returns as tag_name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit 478e0a7 into developMay 7, 2026
16 checks passed
@ptr727
ptr727 deleted the pull-project-alignment branch May 7, 2026 20:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Align dependabot, merge-bot, release flow, and SHA-pin all actions - #692

Merged
ptr727 merged 6 commits into
developfrom
pull-project-alignment
May 7, 2026
Merged

Align dependabot, merge-bot, release flow, and SHA-pin all actions#692
ptr727 merged 6 commits into
developfrom
pull-project-alignment

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Brings PlexCleaner in line with the dual-publish "pull project" pattern adopted by ptr727/ProjectTemplate and ptr727/homeassistant-purpleair.

  • dependabot.yml: also targets develop so both auto-publishing branches stay in sync.
  • merge-bot-pull-request.yml: branch-aware merge method (squash for develop, merge for main) + App-token auth so post-merge pushes trigger publish workflows on develop instead of being skipped by GitHub's recursion guard.
  • build-release-task.yml: target_commitish=github.sha so release tags land on the triggering commit (not main's tip when triggered from develop) + fail_on_unmatched_files.
  • All workflows: every third-party action pinned to a commit SHA with # vX.Y.Z comment; dotnet/nbgv@master replaced with @v0.5.1.
  • AGENTS.md + copilot-instructions.md: document branch flow, merge strategy split, dual-publish release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.

Branch rulesets and repo merge settings have already been updated via gh api to match (rebase disabled, auto-merge enabled, develop = squash-only + linear history, main = merge-only, both with Check pull request workflow status as the required check).

Test plan

  • CI green (test-pull-request workflow)
  • Copilot review threads resolved (required by ruleset)
  • Squash-merge into develop (only method allowed by new develop ruleset) → triggers publish-release.yml and produces a develop prerelease
  • Confirm release tag points at the develop commit SHA (verifies target_commitish fix)

🤖 Generated with Claude Code

ptr727and others added 3 commits May 7, 2026 12:51
- dependabot.yml: also target develop so both auto-publishing branches
stay on the same baseline.
- merge-bot-pull-request.yml: branch-aware merge method (squash for
develop, merge for main) and App-token auth so post-merge pushes
trigger publish-release and publish-periodic-docker-release on
develop instead of being skipped by GitHub's recursion guard.
- build-release-task.yml: set target_commitish=github.sha so release
tags land on the triggering commit, not the repo default branch;
fail_on_unmatched_files; pin softprops/action-gh-release to v3.0.0.
- AGENTS.md: document the feature->develop->main flow, develop->main
promotion via merge commit, dual-publish release flow, dependabot
rationale, and merge-bot design.
- copilot-instructions.md: terse summary section pointing at AGENTS.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace floating major-version refs (@v5/@v6/@v7/@v8/@v3/@v4/@v1) and
the @master ref on dotnet/nbgv with full commit SHAs plus version
comments, matching the pattern already used for create-github-app-token,
fetch-metadata, and softprops/action-gh-release. Pins make supply-chain
attacks via tag mutation impossible and let dependabot bump them
mechanically.
Also drops the verbose target_commitish rationale comment from
build-release-task.yml; the field is self-explanatory in this repo's
context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The previous commit pinned every third-party action to a commit SHA but
didn't capture the rule itself. Add a "GitHub Actions pinning" section
to AGENTS.md explaining what to pin, why floating tags are unsafe, and
how to resolve a SHA when adding a new action. Add a one-line summary
to copilot-instructions.md so AI agents don't reintroduce floating
refs in suggestions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings May 7, 2026 20:06

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates PlexCleaner’s automation to match a dual-branch (develop/main) “pull project” release model, with bot-driven dependency maintenance and hardened GitHub Actions usage (SHA-pinning).

Changes:

  • Extend Dependabot to target both main and develop, and update merge-bot behavior to be branch-aware (squash to develop, merge-commit to main) using an App token.
  • Fix release tagging behavior by setting target_commitish: ${{ github.sha }} and tighten release asset upload behavior with fail_on_unmatched_files.
  • Pin third-party GitHub Actions to immutable commit SHAs across workflows and document the branch/release/bot policies.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
AGENTS.mdDocuments branch flow, release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.
.github/copilot-instructions.mdAdds concise guidance for agents on branching/release strategy and action pinning.
.github/dependabot.ymlAdds parallel Dependabot update configs for develop in addition to main.
.github/workflows/merge-bot-pull-request.ymlUses App token and selects merge method based on base branch rules.
.github/workflows/build-release-task.ymlPins actions; ensures release tags target the triggering commit and fails on missing assets.
.github/workflows/get-version-task.ymlPins actions and replaces floating dotnet/nbgv@master with a versioned SHA pin.
.github/workflows/build-executable-task.ymlPins setup-dotnet/checkout/artifact actions.
.github/workflows/build-docker-task.ymlPins docker setup/login/build actions.
.github/workflows/publish-periodic-docker-release.ymlPins actions for docker-run, artifacts, checkout, download-artifact, and dockerhub description.
.github/workflows/build-datebadge-task.ymlPins BYOB action to a commit SHA.
.github/workflows/test-release-task.ymlPins setup-dotnet and checkout actions.

Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Every other workflow file in the repo uses the over-indented YAML style
where list items under `steps:` are at parent_indent+2 (e.g., `steps:`
at column 4, `- name:` at column 6). This file alone used the compact
style with both at the same column. Both are valid YAML and GitHub
Actions accepts either, but consistency matters more than syntactic
flexibility. Bring this file in line with the other six.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/merge-bot-pull-request.yml
Comment thread.github/workflows/publish-periodic-docker-release.yml
Two clarifications surfaced by Copilot review on PR #692:
1. The merge-bot uses an App token minted from CODEGEN_APP_*
secrets. For Dependabot-authored pull_request events, GitHub only
exposes secrets from the Dependabot namespace (Settings → Secrets
→ Dependabot), not the regular Actions namespace. The secrets must
exist in both, or the App-token step gets empty inputs at runtime.
This is non-obvious and worth calling out explicitly so future
maintainers don't strip the Dependabot duplicate as redundant.
2. The SHA-pinning comment convention is "match the upstream release
tag" — usually # vX.Y.Z, but # v3 (or # master) when upstream only
publishes major-only / branch tags. Don't fabricate a semver
suffix; use what gh api repos/<owner>/<repo>/releases/latest
returns as tag_name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit 478e0a7 into developMay 7, 2026
16 checks passed
@ptr727
ptr727 deleted the pull-project-alignment branch May 7, 2026 20:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Align dependabot, merge-bot, release flow, and SHA-pin all actions - #692

Merged
ptr727 merged 6 commits into
developfrom
pull-project-alignment
May 7, 2026
Merged

Align dependabot, merge-bot, release flow, and SHA-pin all actions#692
ptr727 merged 6 commits into
developfrom
pull-project-alignment

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Brings PlexCleaner in line with the dual-publish "pull project" pattern adopted by ptr727/ProjectTemplate and ptr727/homeassistant-purpleair.

  • dependabot.yml: also targets develop so both auto-publishing branches stay in sync.
  • merge-bot-pull-request.yml: branch-aware merge method (squash for develop, merge for main) + App-token auth so post-merge pushes trigger publish workflows on develop instead of being skipped by GitHub's recursion guard.
  • build-release-task.yml: target_commitish=github.sha so release tags land on the triggering commit (not main's tip when triggered from develop) + fail_on_unmatched_files.
  • All workflows: every third-party action pinned to a commit SHA with # vX.Y.Z comment; dotnet/nbgv@master replaced with @v0.5.1.
  • AGENTS.md + copilot-instructions.md: document branch flow, merge strategy split, dual-publish release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.

Branch rulesets and repo merge settings have already been updated via gh api to match (rebase disabled, auto-merge enabled, develop = squash-only + linear history, main = merge-only, both with Check pull request workflow status as the required check).

Test plan

  • CI green (test-pull-request workflow)
  • Copilot review threads resolved (required by ruleset)
  • Squash-merge into develop (only method allowed by new develop ruleset) → triggers publish-release.yml and produces a develop prerelease
  • Confirm release tag points at the develop commit SHA (verifies target_commitish fix)

🤖 Generated with Claude Code

ptr727and others added 3 commits May 7, 2026 12:51
- dependabot.yml: also target develop so both auto-publishing branches
stay on the same baseline.
- merge-bot-pull-request.yml: branch-aware merge method (squash for
develop, merge for main) and App-token auth so post-merge pushes
trigger publish-release and publish-periodic-docker-release on
develop instead of being skipped by GitHub's recursion guard.
- build-release-task.yml: set target_commitish=github.sha so release
tags land on the triggering commit, not the repo default branch;
fail_on_unmatched_files; pin softprops/action-gh-release to v3.0.0.
- AGENTS.md: document the feature->develop->main flow, develop->main
promotion via merge commit, dual-publish release flow, dependabot
rationale, and merge-bot design.
- copilot-instructions.md: terse summary section pointing at AGENTS.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace floating major-version refs (@v5/@v6/@v7/@v8/@v3/@v4/@v1) and
the @master ref on dotnet/nbgv with full commit SHAs plus version
comments, matching the pattern already used for create-github-app-token,
fetch-metadata, and softprops/action-gh-release. Pins make supply-chain
attacks via tag mutation impossible and let dependabot bump them
mechanically.
Also drops the verbose target_commitish rationale comment from
build-release-task.yml; the field is self-explanatory in this repo's
context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The previous commit pinned every third-party action to a commit SHA but
didn't capture the rule itself. Add a "GitHub Actions pinning" section
to AGENTS.md explaining what to pin, why floating tags are unsafe, and
how to resolve a SHA when adding a new action. Add a one-line summary
to copilot-instructions.md so AI agents don't reintroduce floating
refs in suggestions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings May 7, 2026 20:06

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates PlexCleaner’s automation to match a dual-branch (develop/main) “pull project” release model, with bot-driven dependency maintenance and hardened GitHub Actions usage (SHA-pinning).

Changes:

  • Extend Dependabot to target both main and develop, and update merge-bot behavior to be branch-aware (squash to develop, merge-commit to main) using an App token.
  • Fix release tagging behavior by setting target_commitish: ${{ github.sha }} and tighten release asset upload behavior with fail_on_unmatched_files.
  • Pin third-party GitHub Actions to immutable commit SHAs across workflows and document the branch/release/bot policies.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
AGENTS.mdDocuments branch flow, release flow, dependabot rationale, merge-bot design, and SHA-pinning policy.
.github/copilot-instructions.mdAdds concise guidance for agents on branching/release strategy and action pinning.
.github/dependabot.ymlAdds parallel Dependabot update configs for develop in addition to main.
.github/workflows/merge-bot-pull-request.ymlUses App token and selects merge method based on base branch rules.
.github/workflows/build-release-task.ymlPins actions; ensures release tags target the triggering commit and fails on missing assets.
.github/workflows/get-version-task.ymlPins actions and replaces floating dotnet/nbgv@master with a versioned SHA pin.
.github/workflows/build-executable-task.ymlPins setup-dotnet/checkout/artifact actions.
.github/workflows/build-docker-task.ymlPins docker setup/login/build actions.
.github/workflows/publish-periodic-docker-release.ymlPins actions for docker-run, artifacts, checkout, download-artifact, and dockerhub description.
.github/workflows/build-datebadge-task.ymlPins BYOB action to a commit SHA.
.github/workflows/test-release-task.ymlPins setup-dotnet and checkout actions.

Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Comment thread.github/workflows/publish-periodic-docker-release.yml Outdated
Every other workflow file in the repo uses the over-indented YAML style
where list items under `steps:` are at parent_indent+2 (e.g., `steps:`
at column 4, `- name:` at column 6). This file alone used the compact
style with both at the same column. Both are valid YAML and GitHub
Actions accepts either, but consistency matters more than syntactic
flexibility. Bring this file in line with the other six.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/merge-bot-pull-request.yml
Comment thread.github/workflows/publish-periodic-docker-release.yml
Two clarifications surfaced by Copilot review on PR #692:
1. The merge-bot uses an App token minted from CODEGEN_APP_*
secrets. For Dependabot-authored pull_request events, GitHub only
exposes secrets from the Dependabot namespace (Settings → Secrets
→ Dependabot), not the regular Actions namespace. The secrets must
exist in both, or the App-token step gets empty inputs at runtime.
This is non-obvious and worth calling out explicitly so future
maintainers don't strip the Dependabot duplicate as redundant.
2. The SHA-pinning comment convention is "match the upstream release
tag" — usually # vX.Y.Z, but # v3 (or # master) when upstream only
publishes major-only / branch tags. Don't fabricate a semver
suffix; use what gh api repos/<owner>/<repo>/releases/latest
returns as tag_name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit 478e0a7 into developMay 7, 2026
16 checks passed
@ptr727
ptr727 deleted the pull-project-alignment branch May 7, 2026 20:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727