Skip to content

Conversation

cisagovbot
Copy link

Lineage Pull Request: CONFLICT

Achtung!!!

Lineage has created this pull request to incorporate new changes found in an upstream repository:

Upstream repository: https://github.com/cisagov/skeleton-python-library.git
Remote branch: HEAD

Check the changes in this pull request to ensure they won't cause issues with your project.

The lineage/skeleton branch has one or more unresolved merge conflicts that you must resolve before merging this pull request!

How to resolve the conflicts

  1. Take ownership of this pull request by removing any other assignees.

  2. Clone the repository locally, and reapply the merge:

    git clone [email protected]:cisagov/trustymail.git trustymail
    cd trustymail
    git remote add skeleton https://github.com/cisagov/skeleton-python-library.git
    git remote set-url --push skeleton no_push
    git switch develop
    git switch --create lineage/skeleton --track origin/develop
    git pull skeleton HEAD
    git status
  3. Review the changes displayed by the status command. Fix any conflicts and possibly incorrect auto-merges.

  4. After resolving each of the conflicts, add your changes to the branch, commit, and push your changes:

    git add .github/dependabot.yml README.md 
    git commit
    git push --force --set-upstream origin lineage/skeleton

    Note that you may append to the default merge commit message that git creates for you, but please do not delete the existing content. It provides useful information about the merge that is being performed.

  5. Wait for all the automated tests to pass.

  6. Confirm each item in the "Pre-approval checklist" below.

  7. Remove any of the checklist items that do not apply.

  8. Ensure every remaining checkbox has been checked.

  9. Mark this draft pull request "Ready for review".

✅ Pre-approval checklist

Remove any of the following that do not apply. If you're unsure about any of these, don't hesitate to ask. We're here to help!

  • ✌️ The conflicts in this pull request have been resolved.
  • All future TODOs are captured in issues, which are referenced in code comments.
  • All relevant type-of-change labels have been added.
  • All relevant repo and/or project documentation has been updated to reflect the changes in this PR.
  • Tests have been added and/or modified to cover the changes in this PR.
  • All new and existing tests pass.
  • Bump major, minor, patch, pre-release, and/or build versions as appropriate via the bump_version script if this repository is versioned and the changes in this PR warrant a version bump.
  • Create a pre-release (necessary if and only if the pre-release version was bumped).

✅ Pre-merge checklist

Remove any of the following that do not apply. These boxes should remain unchecked until the pull request has been approved.

  • Finalize version.

✅ Post-merge checklist

Remove any of the following that do not apply.

  • Create a release (necessary if and only if the version was bumped).

Note

You are seeing this because one of this repository's maintainers has configured Lineage to open pull requests.

For more information:

🛠 Lineage configurations for this project are stored in .github/lineage.yml

📚 Read more about Lineage

mcdonnnj and others added 30 commits May 28, 2025 11:15
This adds a `ci` block to the pre-commit configurations to control the
behavior of the pre-commit.ci GitHub app.
We currently use the `develop` branch as our reference for the
cisagov/setup-env-github-action action in the build workflow. We will
instead use the major version tag which puts our usage of this action
in line with how we use other actions in our workflows.
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 5.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v5)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
This includes updating the dependabot configuration, adding a new
`label-prs.yml` GitHub Actions workflow, and adding a suitable
configuration file for the actions/labeler action used by the
aforementioned workflow.
Bumps [actions/labeler](https://github.com/actions/labeler) from 5 to 6.
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](actions/[email protected])

---
updated-dependencies:
- dependency-name: actions/labeler
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5 to 6.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Instead of using the default labels for the `github-actions` package
ecosystem we specify the labels explicitly. This is done to ensure that
dependabot uses our `github-actions` label instead of the default of
`github_actions`. We must also explicitly specify the `dependencies`
label since we are overriding the default label values.
Change the check from looking for specific text in the version output
to using the `--test` option. This will provide a more robust
implementation of this check that does not have to worry about output
format stability.

Co-authored-by: Copilot <[email protected]>
Use a version tag for `cisagov/setup-env-github-action`
…s/setup-python-6

Bump actions/setup-python from 5 to 6
…s/setup-go-6

Bump actions/setup-go from 5 to 6
…-commit_config

Add a configuration block for pre-commit.ci
Add a configuration to automatically label pull requests
…bels

Adjust the labels dependabot uses for GitHub Actions updates
…eck_logic

Adjust the logic used to check for GNU getopt in the `setup-env` script
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
…s/checkout-5

Bump actions/checkout from 4 to 5
This is done automatically with the `pre-commit autoupdate` command.
A new rule, `MD059/descriptive-link-text`, was added in markdownlint's
0.38.0 release, which itself is used in v0.45.0 of markdownlint-cli. As
such, we must update to conform to the new rule.
This adds labels that are common in downstream repositories to the core
configuration. This will help ensure consistent label availability.
Add a configuration to automatically apply the `docker` label to pull
requests.
jsf9k and others added 11 commits September 22, 2025 09:10
Add more repository labels and expand the auto-labeling configuration
…s/download-artifact-5

Bump actions/download-artifact from 4 to 5
⚠️ CONFLICT! Lineage pull request for: skeleton
We no longer use the Snyk service so it makes sense to remove the
badge.
Currently we only set the flag for build results to the Python version,
but since we test across platforms now we should also separate by the
platform as well.
…/skeleton

# Conflicts:
#	.github/dependabot.yml
#	README.md
@cisagovbot cisagovbot added the upstream update This issue or pull request pulls in upstream updates label Sep 24, 2025
@github-actions github-actions bot added documentation This issue or pull request improves or adds to documentation dependencies Pull requests that update a dependency file github-actions Pull requests that update GitHub Actions code labels Sep 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file documentation This issue or pull request improves or adds to documentation github-actions Pull requests that update GitHub Actions code upstream update This issue or pull request pulls in upstream updates
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants