Skip to content

chore(deps): bump fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml from 0.41.0 to 0.43.0 - #107

Merged
em-redhat merged 1 commit into
mainfrom
dependabot/github_actions/fullsend-ai/fullsend/dot-github/workflows/reusable-dispatch.yml-0.43.0
Sep 17, 2026
Merged

em-redhat merged 1 commit into
mainfrom
dependabot/github_actions/fullsend-ai/fullsend/dot-github/workflows/reusable-dispatch.yml-0.43.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml from 0.41.0 to 0.43.0.

Release notes

Sourced from fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml's releases.

v0.43.0

Changelog

Features

  • b15d96748289e2bd01f891bba9fa80fce5ce9acc: feat(#2823)!: implement named privilege levels under agent roles (@​fullsend-ai-coder[bot])
  • 10ad2a88886909dba045ae3717b8d95058d4d9f8: feat(#6214): add keep_history config option for sticky comments (@​fullsend-ai-coder[bot])
  • 7260ca8fa8e683e2af67947bca06a02e9737a40c: feat(#6458): export eval measurement scores via OTLP (@​ascerra)
  • 9e029bd68059fa180814330d253879e18f83fa33: feat(#6684): add --gitlab-url flag to repos install (@​fullsend-ai-coder[bot])
  • 85aa6dec93dc28b6d22e676a4c5b078c181aff19: feat(#6948): make nextwork markdown output self-describing and ordered (@​fullsend-ai-coder[bot])
  • 587a6ad28c5c4a28d767b24549ca2ef9b7044471: feat(#7065): add --fullsend-binary and --fullsend-source flags to repos install (@​fullsend-ai-coder[bot])
  • 16fc67c7ef6d481837bc069ef351458f8a269b7a: feat(#996): log dropped permissions on role-level downscoping (@​fullsend-ai-coder[bot])
  • b73ee1a166ca5c8dfd2da530185b13d952a0169d: feat(site): serve a custom 404 page for unmatched URLs (@​rh-hemartin)

Bug Fixes

  • bb15574e6da4c40fd3e0ad0aa53e27932cfca3f0: fix(#2187): normalize fix instruction line endings (@​shairevivo)
  • f822037ab5bee30a02c06fb29eaf29ebb6239cac: fix(#325): wait for app page before opening browser during install (@​fullsend-ai-coder[bot])
  • 06ca7e2e711d3d5d585228ce9e72293a6f51cb39: fix(#6425): make isTimeoutError self-contained against context errors (@​fullsend-ai-coder[bot])
  • 2ee14c92cf4c0f5386e925cca5768818bd999d42: fix(#6452): propagate org-level allowed_remote_resources to URL resolution (@​fullsend-ai-coder[bot])
  • 20ee2ff2e793812397c0ddd7c167a148d9b21921: fix(#6458): accumulate OTLP batch export errors (@​ascerra)
  • 911b9bfa3432d1d37e5a791eef2ed8468afb1f38: fix(#6458): address Wayne review on OTLP score export (@​ascerra)
  • 807faa123c2da7c72c29e0917eb416263ae94481: fix(#6458): address Wayne round-2 OTLP score export review (@​ascerra)
  • 8278aeef56488ab67f4893270b7649b0257959e8: fix(#6458): address Wayne round-3 OTLP score export review (@​ascerra)
  • c530e9daa62ac542750ba3ab86c9e7249d911a88: fix(#6458): address Wayne round-4 OTLP score export review (@​ascerra)
  • d8a2edabda81113bf114c19cace2ce0aa614a163: fix(#6458): bound eval explanation independently of content-capture SpanLimits (@​ascerra)
  • a7fbd1695d8275394abd9b64e927b09586129514: fix(#6458): harden OTLP score export (@​ascerra)
  • 17e3154eca82549987565284897129d71a52d6cf: fix(#6458): harden OTLP score export after review (@​ascerra)
  • 19687fbe824ca08c9740cf5f05d60833da65a873: fix(#6458): make awaitCreation/Deletion honor canceled ctx before zero-delay backoff (@​ascerra)
  • e947baaeae5a92517afe0c3d6f236e5914d5fad6: fix(#6458): skip empty OTLP score batches (@​ascerra)
  • 8e75d55f62627a0c3e733bff3807e30f6ab3637f: fix(#6684): explicitly infer --forge=gitlab when --gitlab-url is set (@​fullsend-ai-coder[bot])
  • 52c1c9bad16a0581d25483d29ba6c96b4ac0eed7: fix(#6798): resolve base forge/overlays per-layer before merging into child (@​ggallen)
  • 87da18e244b1b02f099704123d3b1e37d3c7ce15: fix(#7059): preserve provider cancellation errors (@​shairevivo)
  • c5db93bc940a77b2a5856053cfec68b05a6818b9: fix(#7069): add --fullsend-ref flag to github setup command (@​fullsend-ai-coder[bot])
  • 973b78b09b6784462758830b040dadbf6da748ad: fix(#7089): use standard token resolution in lookupAppID (@​fullsend-ai-coder[bot])
  • 45d6603c6251751b33424c26794a54514c3b087f: fix(#7127): accept nested GitLab group paths in repos install (@​fullsend-ai-coder[bot])
  • bc26c9eb4d798c4628f1f1704693674a3e481522: fix(#7127): address review feedback on test adequacy, API shape, and docs (@​fullsend-ai-coder[bot])
  • 39976a4cf6858176dd351430347272f2d9e78d05: fix(#7127): propagate forge-aware validation to uninstall and docs (@​fullsend-ai-coder[bot])
  • 15f5f0de6b3762257612b875a74427ae7567ac69: fix(#7127): update splitOwnerRepo error message and add uninstall docs for nested GitLab paths (@​fullsend-ai-coder[bot])
  • e274a1e57d541018a3370f1b192075914ab034a4: fix(#827): dismiss stale bot approvals (@​shairevivo)
  • b50abd73e34a6b60a6700046534474db26d73669: fix(#827): preserve approval on review failure (@​shairevivo)
  • e8bb94c98407bb065dc04c701bb513fa7eeae9b2: fix(action): restore stderr redirect for first retry_curl workflow commands (@​fullsend-ai-coder[bot])
  • 1301b62ece8f0939f303ccb535775033895adc6c: fix(appsetup): propagate parent context cancellation in ensureInstalled (@​fullsend-ai-coder[bot])
  • 7f08f500ccc42fe8ff66625de47adc5c5c3fb30d: fix(appsetup): return ctx.Err() from waitForAppReady on parent cancellation (@​fullsend-ai-coder[bot])
  • 7f8ba53c0f1323d93f30236e89154629be4e9746: fix(appsetup): use errors.Is for context error comparison (@​fullsend-ai-coder[bot])
  • a3fcaf085742cd928b05cc6f2600c4d37904d673: fix(cli): assert gh auth login suggestion in rate limit test (@​fullsend-ai-coder[bot])
  • d8332254e4ccdd692db6128f74184c9f49169d42: fix(cli): remove no-op applyDeprecatedVendorBinaryFlag from repos install (@​fullsend-ai-coder[bot])
  • da1a04f62490b2903eb5a668eadd8a8c999cbd8c: fix(cli): use t.Cleanup for consistent lookupTokenFn restoration (@​fullsend-ai-coder[bot])
  • e01962437ff64bcaac0a9c3b0b15b344a9ee22f0: fix(docs): add missing link for cross-cutting principle 6 reference (@​fullsend-ai-coder[bot])
  • 1b0892a934b119963159f45cf6ccd776b14473e9: fix(docs): address review feedback on PR #7113 (@​fullsend-ai-coder[bot])
  • 971bdf1f60980b7c13774b48985395e162c47247: fix(docs): address review feedback on SAFE-MCP landscape entry (@​fullsend-ai-coder[bot])
  • 87d484d40de0cd280a2bac4a56e6d4a54aab445b: fix(docs): clarify ADR 0017 cross-reference in PatchPatrol entry (@​fullsend-ai-coder[bot])
  • 74eeaa0ff32e66bf6d5e82e568b471adf8538c0e: fix(docs): move PatchPatrol from Major tools to Others section (@​fullsend-ai-coder[bot])
  • 1ee0f4aa8ba69ccb98f7dd29deab04aa6f1e53b1: fix(docs): move SAFE-MCP section to correct document position (@​fullsend-ai-coder[bot])

... (truncated)

Commits
  • d5f3692 Merge pull request #6459 from fullsend-ai/feat/otlp-score-export
  • de400ef Merge pull request #7116 from fullsend-ai/config-diverse-models
  • 34f2d07 Merge pull request #7153 from fullsend-ai/agent/7152-fix-standalone-mint-clone
  • fd9c57f Merge pull request #7087 from fullsend-ai/agent/6684-gitlab-url-flag
  • 340792b docs(#7152): add git clone step to standalone mint guide
  • 29bb7d4 Merge pull request #7132 from fullsend-ai/agent/7127-gitlab-nested-paths
  • 3da3187 Merge pull request #6454 from fullsend-ai/agent/6452-org-allowlist-policy-res...
  • c752617 Merge pull request #6897 from fullsend-ai/docs/september-roadmap
  • c64055d Merge remote-tracking branch 'origin/main' into feat/otlp-score-export
  • 20ee2ff fix(#6458): accumulate OTLP batch export errors
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…patch.yml

Bumps [fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml](https://github.com/fullsend-ai/fullsend) from 0.41.0 to 0.43.0.
- [Release notes](https://github.com/fullsend-ai/fullsend/releases)
- [Commits](fullsend-ai/fullsend@094191b...d5f3692)

---
updated-dependencies:
- dependency-name: fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml
  dependency-version: 0.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 14, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 14, 2026 17:35
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 14, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:37 PM UTC · Completed 5:47 PM UTC

Commit: cbf7db1 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.21

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 14, 2026
@fullsend-ai-review

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Single-file CI workflow SHA bump by Dependabot bot with minimal change size (2 lines); elevated by CI_WORKFLOW_CHANGED (score 4) and one protected path (score 3), offset by bot authorship, no security-sensitive files, and low git history churn.

@fullsend-ai-review

Copy link
Copy Markdown

Review

Findings

High

  • [protected-path] .github/workflows/fullsend.yaml:48 — This PR modifies .github/workflows/fullsend.yaml, which is under the protected path .github/. The PR has no linked issue providing authorization for governance/infrastructure file changes. Human approval is required for all protected-path modifications.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

Comment thread .github/workflows/fullsend.yaml

@em-redhat em-redhat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@em-redhat
em-redhat merged commit f95f59b into main Sep 17, 2026
80 of 81 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/fullsend-ai/fullsend/dot-github/workflows/reusable-dispatch.yml-0.43.0 branch September 17, 2026 11:14
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 11:15 AM UTC · Completed 11:25 AM UTC

Commit: cbf7db1 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.54

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #107 — Dependabot reusable-dispatch.yml bump (v0.41.0 → v0.43.0)

What happened

Dependabot opened PR #107 on 2026-09-14, bumping the fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml SHA from v0.41.0 to v0.43.0 — a single-line change in one file.

The review agent (run 34875697911) ran for ~12 minutes at a cost of $2.21. It correctly verified both SHAs via the GitHub API, dispatched three sub-agents (correctness, security, style-conventions), and found zero correctness or security issues. The only finding was a HIGH-severity protected-path governance gate: .github/workflows/ is a protected path and the PR had no linked issue providing authorization. The agent submitted CHANGES_REQUESTED.

Three days later, human reviewer em-redhat approved with "lgtm" and merged the PR.

Workflow quality

  • Review quality: The agent's SHA verification was thorough and correct. The protected-path finding is technically accurate per the current rules but adds friction to a zero-risk mechanical change. No false negatives — the change was genuinely safe.
  • Rework rate: Zero iterations needed — the single CHANGES_REQUESTED was resolved by human approval, not by code changes.
  • Token cost: $2.21 is disproportionate for a 1-line bot SHA swap. The correctness sub-agent alone cost $1.70 across 30 turns. The agent did classify the scope as "trivial" but still dispatched three sub-agents.
  • Time to resolution: ~3 days, primarily waiting for human approval of the governance gate.
  • Model error: The risk-assessment sub-agent hit a model availability error (claude-sonnet-4-5@20250929 unavailable) and the orchestrator recovered gracefully by computing the risk assessment inline.

No new proposals — existing issues cover all improvement opportunities

Every improvement angle from this retro is already well-tracked across fullsend-ai/agents and fullsend-ai/fullsend. Filing new proposals would create duplicates.

Protected-path severity for bot PRs: fullsend-ai/fullsend#2588, fullsend-ai/fullsend#5370, fullsend-ai/fullsend#3164, fullsend-ai/agents#741, fullsend-ai/agents#735 — these collectively propose downgrading protected-path severity for mechanical bot dependency bumps and accepting PR body rationale as authorization context.

Lightweight review path for trivial/mechanical changes: fullsend-ai/agents#257 (early exit for bot dependency PRs), fullsend-ai/agents#301 (lightweight path for trivial changes), fullsend-ai/agents#513 (short-circuit for mechanical dependency bumps), fullsend-ai/fullsend#2639 and fullsend-ai/fullsend#3240 (fast-path for trivial bot PRs). This retro provides additional evidence: the correctness sub-agent spent $1.70 / 30 turns on a 1-line SHA swap despite trivial scope classification.

COMMENT vs CHANGES_REQUESTED for governance-only findings: fullsend-ai/fullsend#5369 proposes using COMMENT instead of CHANGES_REQUESTED when findings are governance-only on bot PRs. This would avoid blocking merge while still surfacing the finding.

Model availability fallback: fullsend-ai/agents#1186 (sonnet alias resolves to unavailable model), fullsend-ai/fullsend#7026 (priority/high — no automatic fallback), fullsend-ai/fullsend#1771 and fullsend-ai/fullsend#6964 (validate availability before dispatch). This retro saw the same pattern — the orchestrator's inline fallback worked but the sub-agent attempt was wasted.

Skip retro for trivial bot PRs: fullsend-ai/fullsend#3226 proposes exactly this — this retro run itself is evidence that the optimization is warranted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code risk/moderate PR risk: moderate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants