feat(deps): consolidate 16 open dependency pull requests, install gh, disable debuginfod - #119
Conversation
Bumps ghcr.io/devcontainers/features/github-cli from 1.1.0 to 1.1.2. --- updated-dependencies: - dependency-name: ghcr.io/devcontainers/features/github-cli dependency-version: 1.1.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps ghcr.io/devcontainers/features/desktop-lite from 1.2.9 to 1.2.10. --- updated-dependencies: - dependency-name: ghcr.io/devcontainers/features/desktop-lite dependency-version: 1.2.10 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the npm group with 1 update: [@playwright/test](https://github.com/microsoft/playwright). Updates `@playwright/test` from 1.61.1 to 1.62.1 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.61.1...v1.62.1) --- updated-dependencies: - dependency-name: "@playwright/test" dependency-version: 1.62.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.6.0 to 26.3.0. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.3.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [cmake](https://github.com/scikit-build/cmake-python-distributions) from 4.3.4 to 4.4.2. - [Release notes](https://github.com/scikit-build/cmake-python-distributions/releases) - [Changelog](https://github.com/scikit-build/cmake-python-distributions/blob/main/HISTORY.rst) - [Commits](scikit-build/cmake-python-distributions@4.3.4...4.4.2) --- updated-dependencies: - dependency-name: cmake dependency-version: 4.4.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [conan](https://github.com/conan-io/conan) from 2.30.0 to 2.31.2. - [Release notes](https://github.com/conan-io/conan/releases) - [Commits](conan-io/conan@2.30.0...2.31.2) --- updated-dependencies: - dependency-name: conan dependency-version: 2.31.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the github-actions group with 11 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.19.4` | `2.21.0` | | [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.5.7` | `0.6.2` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.36.2` | `4.37.8` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.3` | `2.4.4` | | [marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment) | `3.0.4` | `3.0.5` | | [crazy-max/ghaction-container-scan](https://github.com/crazy-max/ghaction-container-scan) | `4.0.0` | `4.1.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.1.0` | `4.3.0` | | [docker/login-action](https://github.com/docker/login-action) | `4.2.0` | `4.6.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `6.1.0` | `6.2.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `7.2.0` | `7.3.0` | | [actions/attest](https://github.com/actions/attest) | `4.1.0` | `4.2.2` | Updates `step-security/harden-runner` from 2.19.4 to 2.21.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@9af89fc...05e3151) Updates `zizmorcore/zizmor-action` from 0.5.7 to 0.6.2 - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](zizmorcore/zizmor-action@192e21d...3dc1ecc) Updates `github/codeql-action/upload-sarif` from 4.36.2 to 4.37.8 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@8aad20d...db488dd) Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@4eaacf0...2d11466) Updates `marocchino/sticky-pull-request-comment` from 3.0.4 to 3.0.5 - [Release notes](https://github.com/marocchino/sticky-pull-request-comment/releases) - [Commits](marocchino/sticky-pull-request-comment@0ea0beb...5770ad5) Updates `crazy-max/ghaction-container-scan` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/crazy-max/ghaction-container-scan/releases) - [Commits](crazy-max/ghaction-container-scan@a0a3900...ffcba8d) Updates `docker/setup-buildx-action` from 4.1.0 to 4.3.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@d7f5e7f...37fe631) Updates `docker/login-action` from 4.2.0 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@650006c...dbcb813) Updates `docker/metadata-action` from 6.1.0 to 6.2.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@80c7e94...dc80280) Updates `docker/build-push-action` from 7.2.0 to 7.3.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@f9f3042...53b7df9) Updates `actions/attest` from 4.1.0 to 4.2.2 - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](actions/attest@59d8942...1e69f48) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: zizmorcore/zizmor-action dependency-version: 0.6.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.8 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: marocchino/sticky-pull-request-comment dependency-version: 3.0.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: crazy-max/ghaction-container-scan dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/metadata-action dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/attest dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@48b55a0...8207627) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@27d5ce7...55cc834) --- updated-dependencies: - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/stale](https://github.com/actions/stale) from 10.3.0 to 11.0.0. - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@eb5cf3a...4391f3d) --- updated-dependencies: - dependency-name: actions/stale dependency-version: 11.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [oxsecurity/megalinter/flavors/dotnet](https://github.com/oxsecurity/megalinter) from 9.5.0 to 10.0.0. - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@0e3ce9b...15e5b45) --- updated-dependencies: - dependency-name: oxsecurity/megalinter/flavors/dotnet dependency-version: 10.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…narsource.sonarlint-vscode in devcontainer.json
…urce.sonarlint-vscode in devcontainer.json
Resolved features conflict with #106 by keeping both bumps: desktop-lite 1.2.10 and github-cli 1.1.2.
Resolved requirements.in conflict with #110 by keeping both pins: cmake 4.4.2 and conan 2.31.2. requirements.txt auto-merged to match.
Resolved devDependencies conflict with #108 by keeping both bumps: @playwright/test 1.62.1 and @types/node 26.3.0.
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Max errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 24 | 0 | 0 | 0.5s | ||
| ✅ ACTION | zizmor | 24 | 0 | 0 | 0 | 5.61s | |
| ✅ DOCKERFILE | hadolint | 3 | 0 | 0 | 0.37s | ||
| ✅ JSON | npm-package-json-lint | yes | no | no | 0.76s | ||
| ✅ JSON | prettier | 22 | 3 | 0 | 0 | 0.6s | |
| ✅ JSON | v8r | 22 | 0 | 0 | 10.54s | ||
| ✅ MARKDOWN | markdownlint | 12 | 0 | 0 | 0 | 1.13s | |
| ✅ MARKDOWN | markdown-table-formatter | 12 | 1 | 0 | 0 | 0.31s | |
| ✅ REPOSITORY | betterleaks | yes | no | no | 1.21s | ||
| ✅ REPOSITORY | checkov | yes | no | no | 23.39s | ||
| ✅ REPOSITORY | git_diff | yes | no | no | 0.02s | ||
| ✅ REPOSITORY | grype | yes | no | no | 79.3s | ||
| ✅ REPOSITORY | osv-scanner | yes | no | no | 1.72s | ||
| ✅ REPOSITORY | secretlint | yes | no | no | 2.68s | ||
| ✅ REPOSITORY | syft | yes | no | no | 6.05s | ||
| ✅ REPOSITORY | trivy | yes | no | no | 12.05s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.43s | ||
| ✅ REPOSITORY | trufflehog | yes | no | no | 4.34s | ||
| lychee | 86 | 1 | 0 | 9.97s | |||
| ✅ YAML | prettier | 32 | 0 | 0 | 0 | 2.59s | |
| ✅ YAML | v8r | 32 | 0 | 0 | 10.9s | ||
| ✅ YAML | yamllint | 32 | 0 | 0 | 1.28s |
Detailed Issues
⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........133
🔗 Unique.........112
✅ Successful.....127
⏳ Timeouts.........0
🔀 Redirected......13
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1
Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 30:7) | Rejected status code: 403 Forbidden
Hint: Followed 13 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
Notices
REPOSITORY_KICS. See Removed linters to find their replacements.
See detailed reports in MegaLinter artifacts
You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:
- oxsecurity/megalinter/flavors/salesforce@v10.0.0 (57 linters)
- oxsecurity/megalinter/flavors/javascript@v10.0.0 (62 linters)
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
There was a problem hiding this comment.
🔵 Needs a closer look
It aggregates many dependency and CI workflow bumps (including major-version action updates), so it needs human confirmation via CI results and targeted smoke checks.
Pull request overview
This PR consolidates 16 dependency-update pull requests into a single branch, updating the devcontainer configurations, CI workflows, and test tooling to newer versions while preserving original history via merge commits.
Changes:
- Bump test tooling dependencies (Playwright and Node typings) in
package.json/package-lock.json. - Update multiple GitHub Actions pins across reusable workflows and repo workflows (e.g., harden-runner, cache, stale, docker actions, MegaLinter, CodeQL SARIF upload).
- Refresh devcontainer dependencies and locks (VS Code extensions, devcontainer features, Python requirements, base apt package versions).
File summaries
| File | Description |
|---|---|
| package.json | Bumps @playwright/test and @types/node devDependencies. |
| package-lock.json | Updates resolved versions for Playwright, Node types, and related transitive deps (incl. Node engine requirement). |
| .github/workflows/wc-sanitize-image-name.yml | Updates step-security/harden-runner pin. |
| .github/workflows/wc-publish-templates.yml | Updates harden-runner and docker/login-action pins. |
| .github/workflows/wc-integration-test.yml | Updates harden-runner pins and bumps actions/cache to v6.1.0. |
| .github/workflows/wc-integration-test-podman.yml | Updates harden-runner pin. |
| .github/workflows/wc-integration-test-docker.yml | Updates harden-runner pin. |
| .github/workflows/wc-document-generation.yml | Updates harden-runner pin. |
| .github/workflows/wc-dependency-review.yml | Updates harden-runner pin. |
| .github/workflows/wc-build-push.yml | Updates pins for harden-runner, docker build tooling, metadata, attest, and sticky comment action. |
| .github/workflows/wc-acceptance-test.yml | Updates harden-runner and bumps actions/setup-node to v7. |
| .github/workflows/vulnerability-scan.yml | Updates harden-runner, container scan action, and CodeQL SARIF upload action pins. |
| .github/workflows/update-dependencies.yml | Updates harden-runner pins. |
| .github/workflows/release-please.yml | Updates harden-runner pin. |
| .github/workflows/release-build.yml | Updates harden-runner pins. |
| .github/workflows/pr-report.yml | Updates harden-runner pin. |
| .github/workflows/pr-image-cleanup.yml | Updates harden-runner pins. |
| .github/workflows/pr-conventional-title.yml | Updates harden-runner and sticky comment action pins. |
| .github/workflows/ossf-scorecard.yml | Updates harden-runner, scorecard action, and CodeQL SARIF upload action pins. |
| .github/workflows/linting-formatting.yml | Updates harden-runner, zizmor action, MegaLinter flavor, and CodeQL SARIF upload action pins. |
| .github/workflows/issue-creation-tool-versions.yml | Updates harden-runner pin. |
| .github/workflows/issue-cleanup.yml | Updates harden-runner pin and bumps actions/stale to v11. |
| .github/workflows/image-cleanup.yml | Updates harden-runner pin. |
| .github/workflows/continuous-integration.yml | Updates harden-runner pin. |
| .devcontainer/rust/devcontainer.json | Bumps VS Code extension versions (PR extension, rust-analyzer, SonarLint). |
| .devcontainer/rust/devcontainer-metadata.json | Bumps rust-analyzer version in metadata. |
| .devcontainer/cpp/requirements.txt | Updates pinned Python tool versions and hashes for cmake and conan. |
| .devcontainer/cpp/requirements.in | Updates the input pins for cmake and conan. |
| .devcontainer/cpp/devcontainer.json | Updates devcontainer feature versions and VS Code extension versions. |
| .devcontainer/cpp/devcontainer-metadata.json | Bumps SonarLint version in metadata. |
| .devcontainer/cpp/devcontainer-lock.json | Updates locked digests for updated devcontainer features. |
| .devcontainer/base/apt-requirements.json | Updates gnupg2 package version pin. |
Review details
- Files reviewed: 31/32 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
Addresses part of #104 and a hadolint SC3037 finding. - Set DEBUGINFOD_URLS to an empty string via containerEnv so GDB 17.1+ does not stall trying to reach debuginfod servers. Added to devcontainer-metadata.json so downstream projects consuming the published cpp image inherit it, and to devcontainer.json for this repository's own container, which builds locally without the label. - Replace two 'echo -e' calls with printf. hadolint 2.15.0, shipped by MegaLinter v10, reports SC3037 'In POSIX sh, echo flags are undefined' for the RUN blocks at lines 108 and 178. Verified byte-identical output and that hadolint 2.15.0 is clean afterwards. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016zidWuKvQmXJrRGfYzaN76
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
Test Results 12 files 12 suites 16m 8s ⏱️ Results for commit 5f3d9e9. ♻️ This comment has been updated with latest results. |
Closes part of #104. Adds gh to the version-pinned apt requirements so every flavor inherits it (cpp and rust both build FROM the base image), rather than requiring manual installation after container creation. Pinned to 2.46.0-4, the version in Ubuntu 26.04 universe on both amd64 and arm64. Universe is already relied upon by this list (gnuplot-qt, qt6-base-dev). The update-apt-packages workflow will advance the pin as Ubuntu refreshes the package. Note: #104 proposed the official GitHub CLI apt repository instead, since 2.46.0 is older than upstream. Installing from the Ubuntu archive was chosen deliberately to keep the base image free of third-party apt sources and consistent with the existing version-pinning scheme. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016zidWuKvQmXJrRGfYzaN76
The 'coverage information should be generated when running a testsuite'
test asserted on the literal string:
100% tests passed, 0 tests failed out of 1
As of the cmake 4.3.4 -> 4.4.2 bump in this branch, ctest omits the
', 0 tests failed' clause when nothing failed, and prints:
100% tests passed out of 1
The testsuite itself passed in CI ('1/1 Test #1: test-coverage ...
Passed'); only the expected wording was stale, which failed the test in
all four cpp runs (docker and podman, amd64 and arm64) and so failed the
Publish Test Results job.
Match both wordings with a regular expression. A genuine failure such as
'50% tests passed, 1 tests failed out of 2' still does not match, and
assert_success continues to guard the exit status.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zidWuKvQmXJrRGfYzaN76
Pull Request Report (#119)Static measures
Time related measures
Status check related measures
|
🚀 Hey, I have created a Pull Request
Description of changes
Two things:
Closes #104.
Part 1 — dependency consolidation
Each source PR is brought in as a merge commit, so original authorship and commit messages are preserved.
Included
sonarsource.sonarlint-vscodeindevcontainer-metadata.jsongnupg22.4.8-4ubuntu3 → 2.4.8-4ubuntu3.1oxsecurity/megalinter/flavors/dotnet9.5.0 → 10.0.0actions/stale10.3.0 → 11.0.0actions/cache5.0.5 → 6.1.0actions/setup-node6.4.0 → 7.0.0conan2.30.0 → 2.31.2cmake4.3.4 → 4.4.2@types/node25.6.0 → 26.3.0@playwright/test1.61.1 → 1.62.1devcontainers/features/desktop-lite1.2.9 → 1.2.10devcontainers/features/github-cli1.1.0 → 1.1.2devcontainer.jsondevcontainer.jsonrust-lang.rust-analyzerindevcontainer-metadata.jsonNot included
chore(main): release 7.3.1) — release-please regenerates this PR from the commit history. Folding it into a feature branch would produce a stale changelog and version bump, so it is intentionally left alone and should be handled by release-please after this merges.Conflicts resolved
Four pairs of PRs touched the same lines. In every case both bumps were kept:
.devcontainer/cpp/devcontainer.json(feat: bump ghcr.io/devcontainers/features/github-cli from 1.1.0 to 1.1.2 #106 / feat: bump ghcr.io/devcontainers/features/desktop-lite from 1.2.9 to 1.2.10 #107) → desktop-lite1.2.10+ github-cli1.1.2.devcontainer-lock.jsonauto-merged with both matching digests..devcontainer/cpp/requirements.in(feat: bump cmake from 4.4.2 to 4.4.3 in /.devcontainer #110 / feat: bump conan from 2.31.2 to 2.32.0 in /.devcontainer #111) →cmake==4.4.2+conan==2.31.2.requirements.txtauto-merged to exactly these two pins.package.json/package-lock.json(test(deps): bump @playwright/test from 1.61.1 to 1.62.1 in the npm group #108 / test(deps): bump @types/node from 26.3.0 to 26.4.0 #109) →@playwright/test ^1.62.1+@types/node ^26.3.0. Declared ranges and resolved lock versions verified consistent.Why these PRs were red
Two independent causes, neither of which is a defect in the PRs themselves:
🧹 Lint & Format— every PR. MegaLinter'sv8rstep failed with:v8rfetches the GitHub workflow schema live from SchemaStore. That schema briefly stopped accepting a valuelessworkflow_call:, which is why every PR opened after Sep 1 failed identically whilemain(same file, unchanged) had passed on Aug 31. The current published schema accepts it again —workflow_callis nowoneOf: [{"type": "null"}, {"type": "object", ...}]— so no source change is needed and none was made here.Build jobs — dependabot PRs only. The docker.io login step fails with
unknown: malformed HTTP Authorization headerbecauseusername: dependabot[bot]and the registry password resolves empty: PRs raised by Dependabot do not receive regular repository secrets. This branch is not a Dependabot branch, so those jobs get real credentials here.Part 2 — issue #104 and hadolint
ghCLI in the base imageAdded
"gh": "2.46.0-4"to.devcontainer/base/apt-requirements.json. BothcppandrustbuildFROM ${BASE_IMAGE}, so every flavor inherits it. Universe is already relied upon by this list (gnuplot-qt,qt6-base-dev), and2.46.0-4is the version in Ubuntu 26.04 universe on both amd64 and arm64. Theupdate-apt-packagesworkflow will advance the pin as Ubuntu refreshes it; ajqround-trip of the edited file is byte-identical, so that automation will not reformat it.Note
#104 proposed adding the official GitHub CLI apt repository instead, on the grounds that the Ubuntu package is stale — and it is: Ubuntu 26.04 still ships exactly
2.46.0-4, the same version the issue names, against roughly 2.97 upstream. Installing from the Ubuntu archive was chosen deliberately to keep the base image free of third-party apt sources and consistent with the existing version-pinning scheme. Worth revisiting if a currentghmatters more than that.Note
cpp/devcontainer.jsonalso pulls in theghcr.io/devcontainers/features/github-clifeature, which installs a newerghwhen the devcontainer is built. That feature is now partly redundant, though it still gives cpp devcontainer users a more current binary than the image ships. Left in place.DEBUGINFOD_URLSSet to an empty string via
containerEnv, so GDB 17.1+ does not stall reaching debuginfod servers on every debug session. Added in two places:.devcontainer/cpp/devcontainer-metadata.json— becomes the image'sdevcontainer.metadatalabel, so downstream projects consuming the published cpp image inherit it..devcontainer/cpp/devcontainer.json— this repository's own container builds locally from the Dockerfile and so carries no label.Only the cpp flavor ships gdb, so rust is untouched.
hadolint
SC3037Replaced two
echo -ecalls in.devcontainer/cpp/Dockerfilewithprintf.The trigger is #116 in this same PR: MegaLinter v10 ships hadolint 2.15.0, which reports what 2.13/2.14 did not. Reproduced locally against the pre-change file:
— the same two lines reported in CI. After the change, hadolint 2.15.0 is clean on all three Dockerfiles. Both replacements were verified to produce byte-identical output to the originals.
✔️ Checklist
ghpackage and theDEBUGINFOD_URLSenv var; covered by the existing integration and acceptance suitesghis a version-pinned entry inapt-requirements.jsonand so is picked up by the existing syft/grype scanning; other entries updated indevcontainer-lock.json,requirements.txtandpackage-lock.jsonNote
requirements.txtwas produced by git's merge of two independentpip-compile --generate-hashesoutputs rather than by re-runningpip-compile. The pins and hash blocks are consistent, but regenerating it is worth doing if you want the lock to be byte-for-byte reproducible.Note
Titled
featbecause the set includes changes Dependabot raised asfeat:(conan, cmake, devcontainer features) plus the newghpackage, so a squash-merge still yields the right release-please bump.🤖 Generated with Claude Code
https://claude.ai/code/session_016zidWuKvQmXJrRGfYzaN76