action-allowlist-review: bump runs-on/action from 2.1.0 to 2.1.1 in /.github/actions/for-dependabot-triggered-reviews#809
Conversation
Bumps [runs-on/action](https://github.com/runs-on/action) from 2.1.0 to 2.1.1. - [Release notes](https://github.com/runs-on/action/releases) - [Commits](runs-on/action@742bf56...e46a3c6) --- updated-dependencies: - dependency-name: runs-on/action dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
potiuk
left a comment
There was a problem hiding this comment.
I think this one is pretty much absolutely no go. And I am surprised we have it ...
This action has embedded binary runner images (!!!) for differnet architectures? This sound super dangerous
|
Holding off on approval pending a deeper look. verify-action-build's text-level checks pass cleanly (JS rebuild matches, lock file ✓, downloads verified, source diff is just +181/-118 LOC of real Go code from the maintainer), but |
|
After deeper inspection: holding this as a recommended-reject pending upstream changes.
verify-action-build's "JS rebuild matches" only covers the launcher — there is no part of our pipeline that proves the shipped binaries were built from the published source. One additional concern worth flagging: the upstream I'm filing an upstream issue at runs-on/action requesting |
|
Quick downstream-impact note before any retroactive-review decision:
It's how they configure runs-on.com self-hosted runners for their perf/extended test matrix. So:
|
Bumps runs-on/action from 2.1.0 to 2.1.1.
Release notes
Sourced from runs-on/action's releases.
Commits
e46a3c6dist: rebuild binaries88629fcSend runtime token to Magic Cache config6e9cb2bUpdate actions408de89dist: rebuild binariese8a2e6dRemove dead code: unused MetricSummary fields and calculateMin/calculateMax f...3a86586dist: rebuild binaries61a7be1build: upgrade to go 1.26Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)