chore(deps): bump azure/login from 3.0.0 to 3.0.1 - #3969
Conversation
|
@dependabot rebase |
Bumps [azure/login](https://github.com/azure/login) from 3.0.0 to 3.0.1. - [Release notes](https://github.com/azure/login/releases) - [Commits](Azure/login@532459e...f5d393a) --- updated-dependencies: - dependency-name: azure/login dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
4ec6ae6 to
66468a5
Compare
|
I'd like to look into updating |
Sure, probably a different PR yeah? Any idea why this |
|
different PR for sure. this error message is a mystery to me. we're supplying the appropriate input params and the patch release notes don't provide any clues 🤔 |
|
ah, of course. dependabot doesn't have access to repository secrets. i'll create duplicate values that it can access and rerun the failing job. |
|
Ah yes 🤦 |
|
There was a problem hiding this comment.
i think this one is safe to merge but i'm assigning @lalver1 too so that he can review the terraform plan output and confirm that its safe to deploy the changes it describes to the dev environment.
now that he's load-testing test i think so, but better safe than sorry.
Interesting. I think this is unexpected at least so far as my PR was concerned -- we didn't get any plan summary comment, so I didn't realize anything was changing (beyond the expected SHA). Should we change/remove the path filters for |
personally i don't see what happened here as a bug. the drift on
|
|
Agreed not a bug per-se, but it highlights an issue that It is always possible DevSecOps twiddles some nobs and those changes don't make their way down to our Terraform, or something else (more nefarious maybe??) I still think over-communication here is better than an |
i can get behind that, but its worth noting that even time itself (between the last commit pushed and a PRs eventual merge) opens us up to the potential of another cool option might be to consider surfacing https://github.com/cal-itp/benefits/actions/runs/31639968999 |
Fair enough. This all raises a related question for me, that isn't a new issue, but maybe still worth discussing: How do we know what changes will I think we can leave it here for now, and maybe revisit all of this in a future Workshop convo. |
Bumps azure/login from 3.0.0 to 3.0.1.
Release notes
Sourced from azure/login's releases.
Commits
f5d393aMerge remote-tracking branch 'origin/master' into releases/v3.0.1e8cd11fReplacing hardcoded version v2 with v3 (#603)73730b8prepare release v3.0.1f4dcb80Escape single quotes in PowerShell login script inputs (#599)e82415aAdd IDE files to .gitignore (#597)a842007Update CODEOWNERS (#598)9dfca58use the latest auzre/powershell@v3 (#581)