fix(ci): adopt dependabot-rebase standard (correct SHA + dispatch trigger)#194
fix(ci): adopt dependabot-rebase standard (correct SHA + dispatch trigger)#194
Conversation
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 45 minutes and 47 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
There was a problem hiding this comment.
Pull request overview
Updates the repository’s Dependabot rebase workflow stub to align with the org-standard caller, ensuring the reusable workflow is pinned correctly and can be manually invoked when needed.
Changes:
- Adds a
workflow_dispatchtrigger for manually running the Dependabot rebase workflow. - Updates the reusable workflow reference to a pinned SHA and adjusts the secrets/permissions blocks to match the standard stub.
| secrets: | ||
| APP_ID: ${{ secrets.APP_ID }} | ||
| APP_PRIVATE_KEY: ${{ secrets.APP_PRIVATE_KEY }} |
There was a problem hiding this comment.
The header comment still says "Required org/repo secrets (inherited)", but this workflow now passes APP_ID/APP_PRIVATE_KEY via an explicit secrets: mapping (not secrets: inherit). Please update the comment to avoid misleading future maintainers about how secrets are provided to the reusable workflow.
Automated review — APPROVEDRisk: LOW SummaryThis PR is a net security improvement: it pins the reusable workflow to an immutable SHA (replacing mutable @v1 tag), replaces FindingsMinor
Info
CI status
Reviewed by the don-petry PR-review cascade (triage: haiku 4.5 → deep: sonnet 4.6 + duck: gpt-5.4 → audit: opus 4.6). Reply with |



Adopts standards/workflows/dependabot-rebase.yml verbatim. Pins reusable to correct SHA 3c6335c0a214bba940bbcbc4346e9d4ab0cb63e1, adds workflow_dispatch trigger, fixes permissions/secrets block. Supersedes prior SHA-pinning and dispatch PRs.