Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
version: 2
updates:
# Keep GitHub Actions current so SHA-pinned actions don't rot and floating major tags get
# reviewed bumps rather than implicit ones. Runner deprecations (e.g. the Node 20 -> 24
# migration) land here first, so this is the early-warning channel for CI breakage.
#
# Caveat: the github-actions ecosystem only tracks `uses: owner/repo@ref`. The actionlint
# step in ci.yml uses a `docker://` reference, which Dependabot does not update — bump
# rhysd/actionlint by hand.
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
groups:
github-actions:
patterns:
- "*"
commit-message:
# This repo's history uses bare conventional-commit types (no scopes) -> "ci: bump …".
prefix: ci
12 changes: 6 additions & 6 deletions .github/workflows/audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ on:
claude-code-version:
description: Pinned @anthropic-ai/claude-code npm version
type: string
default: '2.1.209'
default: '2.1.220'
anthropic-base-url:
description: Gateway base URL (empty = Anthropic default endpoint)
type: string
Expand Down Expand Up @@ -103,7 +103,7 @@ jobs:
# not_configured | skip_marker | no_source_changes | '' (empty when run=true)
skip_reason: ${{ steps.decide.outputs.skip_reason }}
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
fetch-depth: 0

Expand Down Expand Up @@ -188,7 +188,7 @@ jobs:
group: docs-sentinel-pr-${{ github.event.pull_request.number }}
cancel-in-progress: true
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
ref: ${{ github.head_ref }} # PR branch tip so we can push back
fetch-depth: 0 # default GITHUB_TOKEN creds -> push does NOT re-trigger CI
Expand Down Expand Up @@ -336,7 +336,7 @@ jobs:
# Always leave a single, sticky status comment — drift or not — so every PR shows the
# docs-sentinel result instead of going silent when there's nothing to fix.
- name: Post docs-sentinel status comment (sticky)
uses: actions/github-script@v7
uses: actions/github-script@v9
env:
CHANGED: ${{ steps.guard.outputs.changed }}
BODY_PATH: ${{ steps.compose.outputs.body_path }}
Expand Down Expand Up @@ -391,7 +391,7 @@ jobs:
cancel-in-progress: true
steps:
- name: Post docs-sentinel status comment (sticky)
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const marker = '<!-- docs-sentinel-status -->';
Expand Down Expand Up @@ -427,7 +427,7 @@ jobs:
group: docs-sentinel-main
cancel-in-progress: false # never cancel a half-opened PR
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
fetch-depth: 0

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
- name: Install bats + shellcheck
run: sudo apt-get update -q && sudo apt-get install -y -q bats shellcheck
- name: Shellcheck engine scripts
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@ All inputs are optional.
| `diff-exclude` | common lockfiles | File patterns excluded from the diff text shown to the auditor |
| `sync-branch` | `docs/sync` | Fixed branch for the rolling docs-sync PR |
| `runner` | `ubuntu-latest` | Runner label for all jobs |
| `claude-code-version` | `2.1.209` | Pinned `@anthropic-ai/claude-code` npm version |
| `claude-code-version` | `2.1.220` | Pinned `@anthropic-ai/claude-code` npm version |
| `anthropic-base-url` | `https://openrouter.ai/api` | Model gateway base URL |
| `model` | `z-ai/glm-5.2` | Main auditor model |
| `small-model` | `deepseek/deepseek-v4-flash` | Background/summarization model |
Expand Down