Skip to content

fix(docs): correct runbook Client ID wording and rewrap dependabot-repair header comment - #970

Merged
drmoisan merged 6 commits into
mainfrom
bug/dependabot-repair-runbook-and-workflow-comment-wording-952
Oct 2, 2026
Merged

drmoisan merged 6 commits into
mainfrom
bug/dependabot-repair-runbook-and-workflow-comment-wording-952

Conversation

@drmoisan

@drmoisan drmoisan commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Suggested title

fix(docs): correct the runbook sources line to Client ID and rewrap the dependabot-repair header comment

Summary

  • Corrects one line of the GitHub App installation token runbook: the sources line now reads Client ID location (steps 10–12) in place of App ID location (steps 10–12), matching the credential the runbook steps 10 and 22 and the workflow YAML sample use.
  • Rewraps the four-line header comment of .github/workflows/dependabot-repair.yml into five comment lines of at most 100 characters each. The wording is unchanged and no YAML key, value or non-comment line changes.
  • Documentation and comment-only change. No production or test code is touched.

Why

The runbook sources line still described the credential as the App ID after the runbook and workflow moved to the Client ID, and one comment line in the workflow header was 145 characters wide. Both were recorded as residual wording defects in issue 952.

What Changed

  • Runbook (docs/features/active/2026-09-19-dependabot-fanout-and-ci-failing-nuget-upgrades-911/runbooks/github-app-installation-token.runbook.md): line 301, App ID location becomes Client ID location. Line 102, which legitimately refers to the numeric App ID, is unchanged.
  • Workflow (.github/workflows/dependabot-repair.yml): header comment lines 13 to 16 become five comment lines (lines 13 to 17). The file grows from 173 to 174 lines.
  • Feature folder docs/features/active/2026-09-30-dependabot-repair-runbook-and-workflow-comment-wording-952/: plan, evidence artifacts, and policy, code and feature audit artifacts.

Architecture / How It Fits Together

No wiring changes. The workflow remains triggered by workflow_run on completion of the CI workflow and filtered to dependabot/ head branches.

Verification

Completed (from the evidence artifacts in the feature folder):

  • Runbook token census: App ID location occurs on 0 lines, Client ID location (steps 10 on 1 line, and the only remaining App ID line is line 102.
  • Runbook diff against origin/main: 1 line added, 1 removed.
  • Workflow comment width: maximum comment line 99 characters (baseline 145); the five-line block reproduces the original paragraph word for word.
  • Workflow diff against origin/main: 4 lines added, 3 removed, every changed line a comment line.
  • actionlint 1.7.7 over the repository workflows: exit 0, no output.
  • PoshQC test over the two Pester files that read these files: ok: true. Pester pass and total counts are not recorded locally and are read from the CI Pester job on this head.
  • Reduced audit (policy, code review, feature audit): 0 blocking findings.

Recommended:

  • Confirm the CI run on the final head is green, including the actionlint job. This run is the evidence for the modified-workflow-needs-green-run rule (acceptance criterion 5); dependabot-repair.yml defines no workflow_dispatch trigger, so no run of that workflow can occur against this branch.

Backward Compatibility / Migration Notes

None. Documentation and comment text only.

Risks and Mitigations

  • Risk: an unintended non-comment change in the workflow. Mitigation: the anchored diff shows only #-prefixed added and removed lines, and actionlint passes.
  • Rollback: revert the commit.

Review Guide

  1. The two edited files (one line, one five-line comment block).
  2. The audit artifacts in the feature folder.
  3. Evidence under the feature folder evidence/ tree is mechanical output and can be skimmed.

Follow-ups

  • The workflow secret name DEPENDABOT_REPAIR_APP_ID still contains APP_ID although it stores the Client ID. Renaming it touches repository configuration and is out of scope here (reported by the code review as informational).

GitHub Auto-close

  • None

drmoisan and others added 6 commits October 2, 2026 00:39
…x with a preflight-cleared minimal-audit plan

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ent rewrap

Phase 1 edits with verification evidence; AC1 to AC4 checked off.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…locking)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@drmoisan
drmoisan merged commit ab14b12 into main Oct 2, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant