Repository navigation
Support hostname-aware lockfiles for data residency - #137
Merged
Merged
Conversation
Route new tenant dependencies to public dotcom only on repository absence. Preserve hostname and host-local IDs, isolate public requests from tenant credentials, and refuse incomplete generation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Ignore only NOT_FOUND on the queried action metadata fields, while preserving other field failures. Match live integration expectations to the hostname-aware schema. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Positive generation scenarios must not scan the deliberate orphan-commit workflow now that incomplete resolution prevents all writes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Ordinary generation preserves recorded pins. Recommend the explicit refresh option without accepting unreachable pins. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Document plain-command setup, host and token precedence, safe troubleshooting, and unreleased availability. Surface auth guidance in help without changing override or failure behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove GHES setup guidance and support implications from customer docs and help. Runtime host and authentication behavior is unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep explicit dotcom and tenant hosts for Proxima generation. Dotcom saves retain v0.0.3 and omit the implicit github.com field without changing dependency identities. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep public dotcom pins explicit on Proxima and verify recorded repository IDs before reusing tenant-side pins. Preserve legacy dotcom bindings during migration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Interpret omitted hosts as github.com in all schemas. Keep identity verification before Proxima pin reuse and document migration of tenant pins lacking provenance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Undo the explicit-tenant-host change. Only dotcom dependencies resolved from a Proxima root receive a hostname field. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
5 tasks
nodeselector
added a commit
to nodeselector/dependabot-core
that referenced
this pull request
Oct 8, 2026
Builds github/gh-actions-lock#137 at c5ee15d from source; no release exists for this SHA. Swap back to a release pin before review. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
nodeselector
added this pull request to stack #141
October 8, 2026 22:27
Match lockfile output rules without dropping internal host provenance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Route tenant and dotcom HTTPS hosts through a loopback stub tunnel. Cover mixed composite generation, credential isolation, and missing-ref/auth failures without live tokens. Keep only the tenant getting-started documentation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the getting-started documentation trim and existing Go coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve pins referenced by current workflows before pruning, including renamed workflows and transitive dependencies. Keep partial and read-only scans unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
Tenant 404 fallback can select an unintended public namesake, and local verification mishandles mixed-case tenant hostnames.
3 open findings
What changed in this PR
Adds hostname-aware v0.0.3 lockfiles for GitHub Enterprise Cloud data-residency tenants.
Changes:
- Adds tenant/dotcom host routing and repository identity verification.
- Propagates hostnames through resolution, lockfiles, JSON, and URLs.
- Expands documentation and automated coverage for tenant behavior.
| File | Description |
|---|---|
README.md |
Documents data-residency setup and GHES status. |
go.mod |
Upgrades the lockfile library. |
go.sum |
Updates dependency checksums. |
test/scenarios/catalog.yml |
Updates schema expectations and live scenarios. |
internal/dep/dependency.go |
Adds dependency hostname metadata. |
internal/ghapi/client.go |
Creates tenant and anonymous dotcom clients. |
internal/ghapi/hosts.go |
Implements repository host selection. |
internal/ghapi/hosts_test.go |
Tests host routing and trust boundaries. |
internal/ghapi/repos.go |
Routes repository operations by host. |
internal/ghapi/rest_fallback.go |
Hardens anonymous fallback behavior. |
internal/ghapi/tagsource.go |
Routes release and commit queries. |
internal/ghapi/graphql_action_files.go |
Groups resolution by host and handles GraphQL errors. |
internal/ghapi/graphql_action_files_test.go |
Tests action-file error handling. |
internal/ghapi/graphql_peel.go |
Routes tag peeling by host. |
internal/ghapi/graphql_reachability.go |
Routes reachability queries by host. |
internal/resolve/resolver.go |
Seeds hosts and validates metadata routing. |
internal/resolve/discovery.go |
Records resolved dependency hostnames. |
internal/pipeline/diagnose.go |
Adds hostnames to findings and remediation URLs. |
internal/pipeline/diagnose_test.go |
Updates metadata resolver test interface. |
internal/pipeline/checks/misleading.go |
Corrects relock remediation guidance. |
internal/pin/record.go |
Records and deduplicates by hostname. |
internal/pin/plan.go |
Preserves hosts and rejects incomplete graphs. |
internal/pin/plan_test.go |
Updates partial-resolution expectations. |
internal/pin/commit.go |
Carries hostnames into committed dependencies. |
internal/pin/retain_impostor_test.go |
Updates metadata resolver test interface. |
internal/lockfile/state.go |
Implements host binding, verification, and pruning. |
internal/lockfile/state_marshal.go |
Emits v0.0.3 hostname fields deterministically. |
internal/lockfile/state_test.go |
Updates metadata resolver test interface. |
internal/lockfile/hosts_test.go |
Tests schema and host compatibility behavior. |
cmd/gh-actions-lock/root.go |
Documents host selection and authentication. |
cmd/gh-actions-lock/run.go |
Wires host verification and incomplete-plan handling. |
cmd/gh-actions-lock/verify.go |
Applies host semantics to local verification. |
cmd/gh-actions-lock/pin_summary.go |
Generates host-aware summary links. |
cmd/gh-actions-lock/proxima_test.go |
Adds tenant command integration coverage. |
cmd/gh-actions-lock/prune_workflow_test.go |
Tests pruning before host verification. |
cmd/gh-actions-lock/command_test.go |
Tests help and remediation output. |
cmd/gh-actions-lock/format/url.go |
Generates host-aware dependency URLs. |
cmd/gh-actions-lock/format/url_test.go |
Tests tenant release URLs. |
cmd/gh-actions-lock/format/terminal.go |
Renders host-aware terminal links. |
cmd/gh-actions-lock/format/json.go |
Adds conditional hostname JSON fields. |
cmd/gh-actions-lock/format/json_test.go |
Tests JSON hostname serialization. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Clarify that an omitted dependency hostname means the invocation's home host. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



We're getting ready to support lockfiles on ghe.com. That means we'd like to explicitly decorate actions that will be resolved on github.com. This PR brings lockfile schema version v0.0.3 which adds the
hostnamefield. The field will usually be unset and in that case means the workflows "home" tenant (github.com or ghe.com). Today no value set here is meaningful except forgithub.comwhen the workflow is homed on ghe.com. When set the actions will not be resolved on the ghe.com home tenant, and will be resolved on the github.com tenant.