From 683f66c21bdacbb341ecde451a664f13c40b4869 Mon Sep 17 00:00:00 2001 From: Matt Miller Date: Fri, 18 Sep 2026 00:41:42 +0000 Subject: [PATCH] ci(cursor-review): re-sync workflows_ref to the pinned uses: SHA The caller pins the cursor-review reusable twice: the `uses:` SHA selects the workflow definition and the `workflows_ref:` input selects the prompts/scripts loaded at run time. Two Dependabot bumps rewrote `uses:` only, leaving the two 30 commits apart, so the job ran one commit's workflow against another commit's assets (11 files differ across the cursor-review surface between them). Point `workflows_ref:` at the SHA `uses:` already holds and correct the stale trailing comment. The resulting file is byte-identical to the state the caller-fleet bot's own bump PR would have produced. Also stop Dependabot from re-splitting the pair: it only understands `uses:`, so every future bump recreates this. Both ignore entries are needed - a reusable is named by its full path, and a bare `dependency-name` is an exact match. The upstream bump-callers fleet moves both pins together and opened the matching PR against this repo before, so the pin keeps an owner. --- .github/dependabot.yml | 10 ++++++++++ .github/workflows/ci-cursor-review.yml | 4 ++-- 2 files changed, 12 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 91f59b7..735d79b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -51,3 +51,13 @@ updates: update-types: - "minor" - "patch" + ignore: + # NEVER let Dependabot bump the Comfy-Org/github-workflows reusables: a caller + # pins them TWICE (`uses:` SHA + `workflows_ref:` input) and Dependabot only + # rewrites `uses:`, splitting the pair. The bump-*-callers fleet in + # github-workflows moves both pins together. Both entries are needed: + # Dependabot names a reusable by its FULL path, and a bare `dependency-name` + # is an exact match (the exact form covers `owner/repo`, the `/*` form the + # per-file names). Do NOT collapse to `Comfy-Org/github-workflows*`. + - dependency-name: "Comfy-Org/github-workflows" + - dependency-name: "Comfy-Org/github-workflows/*" diff --git a/.github/workflows/ci-cursor-review.yml b/.github/workflows/ci-cursor-review.yml index aa50102..5c6883c 100644 --- a/.github/workflows/ci-cursor-review.yml +++ b/.github/workflows/ci-cursor-review.yml @@ -35,7 +35,7 @@ jobs: # SHA-pinned. Bump this SHA to pick up upstream changes; keep # `workflows_ref` matching so prompts/scripts load from the same commit as # the workflow definition. - uses: Comfy-Org/github-workflows/.github/workflows/cursor-review.yml@425c154ce5049324ee23ad10e106baeed4cfa31b # github-workflows main (ffcc3f5) + uses: Comfy-Org/github-workflows/.github/workflows/cursor-review.yml@425c154ce5049324ee23ad10e106baeed4cfa31b # github-workflows main (425c154) with: # Repo-specific generated/heavy paths. `extra_generated_globs` is the # right knob rather than `diff_excludes`: it feeds the shared @@ -65,7 +65,7 @@ jobs: src/comfy_low/models/_generated.py assets/** # Load the prompts/scripts from the same ref as `uses:`. - workflows_ref: ffcc3f5b4dfc568e846e769c4f4df4f749c7887b + workflows_ref: 425c154ce5049324ee23ad10e106baeed4cfa31b secrets: CURSOR_API_KEY: ${{ secrets.CURSOR_API_KEY }} # Optional — enables start/complete Slack DMs to the triggerer.