Skip to content

chore(deps): update actions/checkout action to v6 - #20

Closed
renovate[bot] wants to merge 337 commits into
masterfrom
renovate/actions-checkout-6.x
Closed

renovate[bot] wants to merge 337 commits into
masterfrom
renovate/actions-checkout-6.x

Conversation

@renovate

@renovate renovate Bot commented Feb 28, 2026 •

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
actions/checkout action major v4 → v6

Release Notes

actions/checkout (actions/checkout)

v6

Compare Source

v5

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Add three workflow templates for internal dogfood launch:
- Deploy Notification: event trigger on deploy.succeeded → Slack
- New User Onboarding: event trigger on member.added → welcome email
- Daily Audit Digest: cron → query Chronicle → email summary
These files were referenced by committed code but never tracked,
breaking Docker/CI builds that clone from git.
- Add requestId to GraphQL context via X-Request-Id header or generated ID
- Improve authentication plugin logic
- Update OAuth routes
- Fix cron and polling trigger handling
- Refresh integration catalog
- Update workflow template seeds
- Misc server and webhook handler cleanup
…orkflow helper

Replace scattered inline Hatchet.init() blocks and hatchet.event.push("workflow:execute") calls in api.ts, webhooks.ts, cron.ts, and polling.ts with the shared dispatchWorkflow helper. Remove dispatch.ts from Knip ignore list now that it is wired into callers.
Make command nullable and add transport (default stdio), url, and headers
columns to support SSE and HTTP remote transport configurations.
POST /api/v1/plugins/upload accepts multipart form-data with a WASM binary,
computes SHA256, uploads to S3 (PLUGIN_STORAGE_BUCKET), injects the public
URL into the manifest, and inserts the plugin record into pluginTable.
- Extract `validateApiKey` into `src/lib/auth/apiKey.ts` and import it in both `api.ts` and `routes/plugins.ts` to eliminate duplication
- Reject requests where `manifest.wasm` is pre-populated (reserved field)
- Add `PLUGIN_STORAGE_BASE_URL` env var for S3-compatible store URL override
- Move `S3Client` instantiation inside the handler after the bucket guard
- Add 10MB file size limit to the WASM upload field
- Add success-path `logger.info` after plugin insert
All features open on all tiers per open-source parity model.
Plugin creation now only enforces the max_plugins count limit,
not a plan-tier feature flag. Removes unused isFeatureEnabled helper.
@renovate
renovate Bot force-pushed the renovate/actions-checkout-6.x branch from a591bee to 9b85b21 Compare March 31, 2026 17:53
GATEKEEPER_ -> AUTH_, AETHER_ -> BILLING_. Core infra env vars should
describe their use case, not their internal product name.
@renovate
renovate Bot force-pushed the renovate/actions-checkout-6.x branch from 9b85b21 to 2e491b3 Compare April 4, 2026 07:20
coopbri added 3 commits April 7, 2026 12:40
…e and quote events

Route mantle.invoice.* and mantle.quote.* events to MyFi's /api/webhooks/mantle endpoint for automated accounting
The platform has grown beyond 16 internal subscriptions, hitting the previous default
Reads all user-organization memberships from the local DB (synced from
Gatekeeper) and writes the corresponding authorization tuples to the
Warden PDP. Supports --dry-run and --delete-orphans flags, following
the same pattern as Runa's reconciliation scripts.

Usage: bun authz:reconcile
@renovate
renovate Bot force-pushed the renovate/actions-checkout-6.x branch from 2e491b3 to f300ef2 Compare April 9, 2026 16:03
coopbri added 5 commits April 9, 2026 11:25
Add three REST endpoints for external systems (e.g. Hatchet cron) to
check and repair user-organization membership tuple drift between the
DB and Warden PDP:

- GET /api/v1/authz/tuples (expected tuples from DB)
- GET /api/v1/authz/drift (diff expected vs PDP)
- POST /api/v1/authz/reconcile (write missing, optionally delete orphans)
The API was blindly setting status='running' after dispatchWorkflow
returned, but the worker can complete the run before the dispatch
call returns (races of 100ms or less for simple workflows). This
overwrote completed/failed terminal states back to running, leaving
runs stuck forever in the UI.

Add WHERE status='pending' guard so the update only fires if the
worker hasn't already transitioned the state.
…er seats

- Security: drizzle-orm 0.45.1 to 0.45.2 (SQL injection fix)
- Deps: graphql 16.13.2, @sentry/bun 10.48.0, @hatchet-dev/typescript-sdk 1.21.0,
  graphql-yoga 5.21.0, @tanstack/query-core 5.97.0, @temporalio/client 1.16.0
- Auth: propagate idpUserId from Gatekeeper API keys so Warden checks
  run for API key holders (not just session users)
- Billing: hard-enforce MAX_USERS entitlement in IDP webhook handler
  (was warn-only, now rejects when seat limit exceeded)
- Tests: add regression tests for API key authZ propagation and seat enforcement
- Chore: add packageManager field, rename WARDEN_SYNC to AUTHZ_SYNC in locks,
  fix graphql type dedup in schema generation script
@renovate
renovate Bot force-pushed the renovate/actions-checkout-6.x branch from f300ef2 to 5e4320a Compare April 10, 2026 21:00
@renovate
renovate Bot force-pushed the renovate/actions-checkout-6.x branch from 5e4320a to 5d254a5 Compare April 10, 2026 22:00
Add Warden authorization checks to 18 read endpoints and billing
usage metering (recordUsage) to 20 mutation endpoints. Upgrade
dependencies (graphile to stable 1.0.0). Align with Omni template
conventions (package.json metadata, changeset config, husky).

Note: tsc --noEmit has pre-existing PostGraphile v5 type errors
from the graphile RC to stable upgrade that need separate resolution.
@renovate
renovate Bot force-pushed the renovate/actions-checkout-6.x branch from 5d254a5 to f143026 Compare April 11, 2026 02:44
coopbri added 6 commits April 10, 2026 21:51
Add type annotations for graphile 1.0.0 stable API changes:
- Cast fieldArgs.getRaw() returns (AnyInputStep to Step<any>)
- Annotate Drizzle where callback parameters
- Bridge GraphQLSchema type between graphql and graphql-yoga
…illing exports

Close the authorization gap for event subscriptions by adding a GraphQL
plugin that enforces admin+ role and max_subscriptions plan limits on
create/update/delete mutations. Also export checkUsage from the billing
module for worker-side pre-execution limit checks.
Add AUTHZ_API_URL and AUTHZ_SERVICE_KEY to all env config mocks so
the warden/client.ts re-export does not fail when Bun runs multiple
test files in the same process. Expand the wardenSyncPoller mock to
preserve checkPermission behavior and prevent it from stubbing out
the authorize wrapper tests. Add env config mock to execution.test.ts
to prevent the real assertEnv from throwing.
…upgrade deps

Add execution limit check to function invocation to prevent billing bypass.
Add Warden authorize to DLQ list/stats endpoints. Add CLA workflow, changeset
tooling, and source-code validation tests for enforcement coverage.
@renovate
renovate Bot force-pushed the renovate/actions-checkout-6.x branch from f143026 to f09e43e Compare April 11, 2026 18:58
coopbri and others added 2 commits April 11, 2026 18:23
The dep upgrade resolved grafast ^1.0.0-rc.8 to stable 1.0.0, which
has breaking changes in the planning lifecycle (currentLayerPlan).
Pin to exact 1.0.0-rc.8 until PostGraphile v5 reaches stable.
@renovate
renovate Bot force-pushed the renovate/actions-checkout-6.x branch from f09e43e to 8666e9f Compare April 11, 2026 23:24
@coopbri coopbri closed this Apr 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant