Skip to content

chore(deps): bump the organization-build-lock group across 2 directories with 6 updates - #559

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/organization-build-lock-a677583ec4
Closed

chore(deps): bump the organization-build-lock group across 2 directories with 6 updates#559
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/organization-build-lock-a677583ec4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 25, 2026

Copy link
Copy Markdown
Contributor

Bumps the organization-build-lock group with 5 updates in the / directory:

Package From To
Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/acquire-build-lock 1.12.1 1.13.0
Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/release-build-lock 1.12.1 1.13.0
Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-confirmed-unity-cleanup 673eb65e7d863a1a8a8a70882bd980e189d41754 300501e91c9bec81bb9b5a977c22aa5bb2d9b649
Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/check-unity-runner-availability 1.12.1 1.13.0
Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-current-pr-head 1.12.1 1.13.0

Bumps the organization-build-lock group with 1 update in the /.github/actions/return-unity-license directory: Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/classify-unity-cleanup-evidence.

Updates Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/acquire-build-lock from 1.12.1 to 1.13.0

Release notes

Sourced from Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/acquire-build-lock's releases.

v1.13.0

1.13.0 (2026-08-24)

Bug Fixes

  • ci: bound required checks and pin ShellCheck (#207) (ec14cc5), closes #205
  • fail early on unhonorable PR head rate limits (#208) (57634ff), closes #203

Features

Commits
  • 300501e feat(ci): add trusted Unity editor action (#209)
  • 57634ff fix: fail early on unhonorable PR head rate limits (#208)
  • ec14cc5 fix(ci): bound required checks and pin ShellCheck (#207)
  • 22d9f1b docs(progress): record the v1.12.1 release, consumer re-pin, and issue triage...
  • See full diff in compare view

Updates Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/release-build-lock from 1.12.1 to 1.13.0

Release notes

Sourced from Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/release-build-lock's releases.

v1.13.0

1.13.0 (2026-08-24)

Bug Fixes

  • ci: bound required checks and pin ShellCheck (#207) (ec14cc5), closes #205
  • fail early on unhonorable PR head rate limits (#208) (57634ff), closes #203

Features

Commits
  • 300501e feat(ci): add trusted Unity editor action (#209)
  • 57634ff fix: fail early on unhonorable PR head rate limits (#208)
  • ec14cc5 fix(ci): bound required checks and pin ShellCheck (#207)
  • 22d9f1b docs(progress): record the v1.12.1 release, consumer re-pin, and issue triage...
  • See full diff in compare view

Updates Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-confirmed-unity-cleanup from 673eb65e7d863a1a8a8a70882bd980e189d41754 to 300501e91c9bec81bb9b5a977c22aa5bb2d9b649

Commits
  • 300501e feat(ci): add trusted Unity editor action (#209)
  • 57634ff fix: fail early on unhonorable PR head rate limits (#208)
  • ec14cc5 fix(ci): bound required checks and pin ShellCheck (#207)
  • 22d9f1b docs(progress): record the v1.12.1 release, consumer re-pin, and issue triage...
  • 168b8de fix(api): give server-directed waits and credential minting their own budgets...
  • 954d123 fix(release): bound the release retry budget by wall clock (#198)
  • 028c174 chore(ci): Bump golangci/golangci-lint-action from 9.0.0 to 9.3.0 in the othe...
  • c054699 docs: record goal completion audit (#196)
  • 77e9ddf fix(enrollment): accept caller-declared classifier paths (#195)
  • b896dab feat: let a caller declare paths inert to its own Unity build (#194)
  • Additional commits viewable in compare view

Updates Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/check-unity-runner-availability from 1.12.1 to 1.13.0

Release notes

Sourced from Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/check-unity-runner-availability's releases.

v1.13.0

1.13.0 (2026-08-24)

Bug Fixes

  • ci: bound required checks and pin ShellCheck (#207) (ec14cc5), closes #205
  • fail early on unhonorable PR head rate limits (#208) (57634ff), closes #203

Features

Commits
  • 300501e feat(ci): add trusted Unity editor action (#209)
  • 57634ff fix: fail early on unhonorable PR head rate limits (#208)
  • ec14cc5 fix(ci): bound required checks and pin ShellCheck (#207)
  • 22d9f1b docs(progress): record the v1.12.1 release, consumer re-pin, and issue triage...
  • See full diff in compare view

Updates Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-current-pr-head from 1.12.1 to 1.13.0

Release notes

Sourced from Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-current-pr-head's releases.

v1.13.0

1.13.0 (2026-08-24)

Bug Fixes

  • ci: bound required checks and pin ShellCheck (#207) (ec14cc5), closes #205
  • fail early on unhonorable PR head rate limits (#208) (57634ff), closes #203

Features

Commits
  • 300501e feat(ci): add trusted Unity editor action (#209)
  • 57634ff fix: fail early on unhonorable PR head rate limits (#208)
  • ec14cc5 fix(ci): bound required checks and pin ShellCheck (#207)
  • 22d9f1b docs(progress): record the v1.12.1 release, consumer re-pin, and issue triage...
  • See full diff in compare view

Updates Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/classify-unity-cleanup-evidence from 673eb65e7d863a1a8a8a70882bd980e189d41754 to 300501e91c9bec81bb9b5a977c22aa5bb2d9b649

Commits
  • 300501e feat(ci): add trusted Unity editor action (#209)
  • 57634ff fix: fail early on unhonorable PR head rate limits (#208)
  • ec14cc5 fix(ci): bound required checks and pin ShellCheck (#207)
  • 22d9f1b docs(progress): record the v1.12.1 release, consumer re-pin, and issue triage...
  • 168b8de fix(api): give server-directed waits and credential minting their own budgets...
  • 954d123 fix(release): bound the release retry budget by wall clock (#198)
  • 028c174 chore(ci): Bump golangci/golangci-lint-action from 9.0.0 to 9.3.0 in the othe...
  • c054699 docs: record goal completion audit (#196)
  • 77e9ddf fix(enrollment): accept caller-declared classifier paths (#195)
  • b896dab feat: let a caller declare paths inert to its own Unity build (#194)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Note

Medium Risk
Pin-only, but it changes behavior on org Unity lock, license cleanup confirmation, and PR head guards across all licensed CI paths.

Overview
Re-pins every consumer of ambiguous-organization-build-lock from v1.12.1 (and older commit SHAs) to v1.13.0 at commit 300501e91c9bec81bb9b5a977c22aa5bb2d9b649. There are no workflow or composite logic edits—only uses: ref updates.

Coverage spans release, unity-tests (all licensed tiers plus unitypackage smoke), unity-benchmarks, runner-bootstrap, and the local return-unity-license composite’s classify-unity-cleanup-evidence steps. Actions touched include acquire-build-lock, release-build-lock, require-confirmed-unity-cleanup, check-unity-runner-availability, and require-current-pr-head.

Upstream v1.13.0 adds early failure when PR-head checks hit rate limits and internal CI hardening; this repo does not adopt the new trusted Unity editor action in this diff.

Reviewed by Cursor Bugbot for commit b1625ac. Bugbot is set up for automated code reviews on this repo. Configure here.

…ies with 6 updates

Bumps the organization-build-lock group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/acquire-build-lock](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock) | `1.12.1` | `1.13.0` |
| [Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/release-build-lock](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock) | `1.12.1` | `1.13.0` |
| [Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-confirmed-unity-cleanup](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock) | `673eb65e7d863a1a8a8a70882bd980e189d41754` | `300501e91c9bec81bb9b5a977c22aa5bb2d9b649` |
| [Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/check-unity-runner-availability](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock) | `1.12.1` | `1.13.0` |
| [Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-current-pr-head](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock) | `1.12.1` | `1.13.0` |

Bumps the organization-build-lock group with 1 update in the /.github/actions/return-unity-license directory: [Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/classify-unity-cleanup-evidence](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock).


Updates `Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/acquire-build-lock` from 1.12.1 to 1.13.0
- [Release notes](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock/releases)
- [Commits](Ambiguous-Interactive/ambiguous-organization-build-lock@168b8de...300501e)

Updates `Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/release-build-lock` from 1.12.1 to 1.13.0
- [Release notes](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock/releases)
- [Commits](Ambiguous-Interactive/ambiguous-organization-build-lock@168b8de...300501e)

Updates `Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-confirmed-unity-cleanup` from 673eb65e7d863a1a8a8a70882bd980e189d41754 to 300501e91c9bec81bb9b5a977c22aa5bb2d9b649
- [Release notes](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock/releases)
- [Commits](Ambiguous-Interactive/ambiguous-organization-build-lock@673eb65...300501e)

Updates `Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/check-unity-runner-availability` from 1.12.1 to 1.13.0
- [Release notes](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock/releases)
- [Commits](Ambiguous-Interactive/ambiguous-organization-build-lock@168b8de...300501e)

Updates `Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-current-pr-head` from 1.12.1 to 1.13.0
- [Release notes](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock/releases)
- [Commits](Ambiguous-Interactive/ambiguous-organization-build-lock@168b8de...300501e)

Updates `Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/classify-unity-cleanup-evidence` from 673eb65e7d863a1a8a8a70882bd980e189d41754 to 300501e91c9bec81bb9b5a977c22aa5bb2d9b649
- [Release notes](https://github.com/ambiguous-interactive/ambiguous-organization-build-lock/releases)
- [Commits](Ambiguous-Interactive/ambiguous-organization-build-lock@673eb65...300501e)

---
updated-dependencies:
- dependency-name: Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/acquire-build-lock
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: organization-build-lock
- dependency-name: Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/release-build-lock
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: organization-build-lock
- dependency-name: Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-confirmed-unity-cleanup
  dependency-version: 300501e91c9bec81bb9b5a977c22aa5bb2d9b649
  dependency-type: direct:production
  dependency-group: organization-build-lock
- dependency-name: Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/check-unity-runner-availability
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: organization-build-lock
- dependency-name: Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/require-current-pr-head
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: organization-build-lock
- dependency-name: Ambiguous-Interactive/ambiguous-organization-build-lock/.github/actions/classify-unity-cleanup-evidence
  dependency-version: 300501e91c9bec81bb9b5a977c22aa5bb2d9b649
  dependency-type: direct:production
  dependency-group: organization-build-lock
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 25, 2026
@wallstop

Copy link
Copy Markdown
Collaborator

Blocked, with the reason measured rather than guessed — see
#498 for the
full write-up from session 223 (PR #563).

Short version: Contract Suites fails here on
classify-unity-cleanup-evidence@300501e9 requires input 'return-log-digest', and supplying that
digest is not sufficient. Running the real classifier at that commit locally shows it also
requires the return log to sit at an exact run-scoped path
($RUNNER_TEMP/unity-return-<RUN_ID>-<RUN_ATTEMPT>-<suffix>/return-license.log), requires that
directory to hold exactly one entry, and hard-requires Windows for evidence deletion — which two
of the five callers of ./.github/actions/return-unity-license are not (release.yml's unitypackage
export and unity-tests.yml's unitypackage smoke gate both run on ubuntu-latest).

The path check fires before the digest is read, so this bump would move the failure from merge time
to run time rather than removing it. The Linux half is blocked upstream.

Also worth noting for whoever retries: as #356 records, Dependabot runs carry no organization
secrets, so every licensed Unity leg is skipped here. A green check count on this pull request would
not have been evidence either way.

@wallstop

Copy link
Copy Markdown
Collaborator

Why this cannot be merged yet, pinpointed

Checked as part of session 227's sweep, so the next session does not re-investigate it.

Contract Suites is the only failing check, and it fails on exactly two lines:

.github/actions/return-unity-license/action.yml:95:  classify-unity-cleanup-evidence@300501e9
  requires input 'return-log-digest', which this call does not pass.
.github/actions/return-unity-license/action.yml:163: (same)
FAIL  0.3s  build-lock-action-inputs

That is #498 exactly, and
scripts/validate-build-lock-action-inputs.js is doing its job -- catching the incompatibility
before it reaches a licensed run.

Supplying the digest is necessary but not sufficient. Session 223 measured the newer classifier
against this repository's real call sites and found it rejects our return-log path before it ever
reads a digest, requires an exact run-scoped evidence directory, and hard-requires Windows for
evidence deletion -- which two of our five callers are not. So a patch that only adds
return-log-digest would trade this failure for a later one, inside the step that returns a paid
Unity seat.

The four actions that can move already have: acquire-build-lock, release-build-lock and
check-unity-runner-availability are on v1.12.1 on main today.
classify-unity-cleanup-evidence and require-confirmed-unity-cleanup are the two frozen at
673eb65e, and they are the two this bump touches.

Blocked on #498, which is itself blocked on
#411's migration onto the
central return action. Not a Dependabot problem and not rebaseable into green.

@dependabot @github

dependabot Bot commented on behalf of github Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/organization-build-lock-a677583ec4 branch August 26, 2026 21:12
@wallstop

Copy link
Copy Markdown
Collaborator

Incorporated into this week's issue-sweep pull request with #498's return-log-digest change applied on top — these pins cannot move without it, so closing in favor of that. All 31 build-lock call sites now validate green against v1.13.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant