Regenerate third-party licenses on trunk pushes#11370
Merged
andyfeller merged 2 commits intotrunkfrom Aug 1, 2025
Merged
Conversation
Fixes #11270 This commit refactors the work done in #11047 of blocking pull requests for manual `third-party` license updates to having GitHub Actions automatically update it on pushes to `trunk`. This will allow maintainers to streamline Dependabot PR reviews while reducing contributor friction when changing dependencies.
Contributor
There was a problem hiding this comment.
Pull Request Overview
This PR refactors the third-party license management approach by removing license checks from the lint workflow and introducing automated license regeneration on trunk pushes. This change reduces contributor friction while maintaining license compliance through automation.
- Removes manual license checking from pull request validation
- Adds automated license regeneration workflow triggered on trunk pushes
- Streamlines the Dependabot PR review process for maintainers
Reviewed Changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
.github/workflows/third-party-licenses.yml |
New workflow that automatically regenerates third-party licenses when dependencies change on trunk |
.github/workflows/lint.yml |
Removes license checking steps and related path triggers from the lint workflow |
BagToad
reviewed
Jul 24, 2025
This commit makes a few notable changes: 1. Use the GitHub Actions automatic token for committing changes 2. Include workflow file in paths to trigger workflow 3. Checkout the default branch explicitly
BagToad
approved these changes
Aug 1, 2025
Member
BagToad
left a comment
There was a problem hiding this comment.
Looks great to me ✨ Thanks for working through the concurrency concern with me and considering my proposal 🙇 I'm glad we were able to push through the blockers with this one and figure it out. Hopefully this does the trick🤞
tmeijn
pushed a commit
to tmeijn/dotfiles
that referenced
this pull request
Aug 22, 2025
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [cli/cli](https://github.com/cli/cli) | minor | `v2.76.2` -> `v2.78.0` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>cli/cli (cli/cli)</summary> ### [`v2.78.0`](https://github.com/cli/cli/releases/tag/v2.78.0): GitHub CLI 2.78.0 [Compare Source](cli/cli@v2.77.0...v2.78.0) #### ℹ️ Note This release was cut primarily to resolve a Linux package distribution issue. We recommend reviewing [the v2.77.0 release notes](https://github.com/cli/cli/releases/tag/v2.77.0) for the complete set of latest features and fixes. #### What's Changed ##### ✨ Features - Add `--force` flag to `gh run cancel` by [@​ankddev](https://github.com/ankddev) in [#​11513](cli/cli#11513) ##### 🐛 Fixes - Fix failing to release Linux packages (affected v2.77.0). See [v2.77.0](https://github.com/cli/cli/releases/tag/v2.77.0) for more information. **Full Changelog**: <cli/cli@v2.77.0...v2.78.0> ### [`v2.77.0`](https://github.com/cli/cli/releases/tag/v2.77.0): GitHub CLI 2.77.0 [Compare Source](cli/cli@v2.76.2...v2.77.0) ####⚠️ Incomplete Release The v2.77.0 release experienced a failure publishing to our official Linux repos. This is resolved in [v2.78.0](https://github.com/cli/cli/releases/tag/v2.78.0), so we recommend using that release instead. #### What's Changed ##### ✨ Features - Report that v1 classic projects are detected on GHES 3.16.x or older by [@​andyfeller](https://github.com/andyfeller) in [#​11491](cli/cli#11491) - Display v2 projects in `gh issue view` by [@​andyfeller](https://github.com/andyfeller) in [#​11496](cli/cli#11496) - View v2 projects in `gh pr view` output by [@​andyfeller](https://github.com/andyfeller) in [#​11497](cli/cli#11497) - Ensure users can see v2 projects when viewing issues and MRs, avoid v1 projects on GHES 3.17 and newer by [@​andyfeller](https://github.com/andyfeller) in [#​11514](cli/cli#11514) ##### 🐛 Fixes - fix error for ErrReleaseNotFound when fetching ref by [@​ejahnGithub](https://github.com/ejahnGithub) in [#​11451](cli/cli#11451) - add test for FetchRefSHA by [@​ejahnGithub](https://github.com/ejahnGithub) in [#​11481](cli/cli#11481) - Fix `gh repo delete --yes` safety issue when no repository argument provided by [@​Copilot](https://github.com/Copilot) in [#​11536](cli/cli#11536) ##### 📚 Docs & Chores - Improve spam detection evals by [@​babakks](https://github.com/babakks) in [#​11419](cli/cli#11419) - Fix `help wanted` label regexp in CI automation by [@​babakks](https://github.com/babakks) in [#​11423](cli/cli#11423) - Update spam detection to comment on and close issue by [@​andyfeller](https://github.com/andyfeller) in [#​11435](cli/cli#11435) - Adding a note to `gh search` docs to explain the usage of `--` to exclude certain results by [@​Sukhpreet-s](https://github.com/Sukhpreet-s) in [#​11162](cli/cli#11162) - Update issue triage guidelines and label usage by [@​BagToad](https://github.com/BagToad) in [#​11454](cli/cli#11454) - Reorganize installation docs by [@​andyfeller](https://github.com/andyfeller) in [#​11473](cli/cli#11473) - Update govulncheck workflow to scan source code by [@​BagToad](https://github.com/BagToad) in [#​11482](cli/cli#11482) - Hidden trusted root flag for release verify by [@​ejahnGithub](https://github.com/ejahnGithub) in [#​11511](cli/cli#11511) #####Dependencies - Regenerate third-party licenses on trunk pushes by [@​andyfeller](https://github.com/andyfeller) in [#​11370](cli/cli#11370) - Update third-party license versions by [@​BagToad](https://github.com/BagToad) in [#​11557](cli/cli#11557) - Bump Go to 1.24.6 by [@​github-actions](https://github.com/github-actions)\[bot] in [#​11467](cli/cli#11467) - chore(deps): bump github.com/spf13/pflag from 1.0.6 to 1.0.7 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​11319](cli/cli#11319) - chore(deps): bump actions/download-artifact from 4 to 5 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​11458](cli/cli#11458) - chore(deps): bump actions/checkout from 4 to 5 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​11490](cli/cli#11490) - chore(deps): bump github.com/yuin/goldmark from 1.7.12 to 1.7.13 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​11368](cli/cli#11368) - Bump google.golang.org/grpc & other required dependencies by [@​BagToad](https://github.com/BagToad) in [#​11510](cli/cli#11510) - chore(deps): bump google.golang.org/grpc from 1.73.0 to 1.74.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​11367](cli/cli#11367) - chore(deps): bump github.com/cli/go-gh/v2 from 2.12.1 to 2.12.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​11537](cli/cli#11537) - chore(deps): bump github.com/go-viper/mapstructure/v2 from 2.3.0 to 2.4.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​11556](cli/cli#11556) #### New Contributors - [@​Sukhpreet-s](https://github.com/Sukhpreet-s) made their first contribution in [#​11162](cli/cli#11162) - [@​Copilot](https://github.com/Copilot) made their first contribution in [#​11536](cli/cli#11536) **Full Changelog**: <cli/cli@v2.76.2...v2.77.0> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS44Mi4xIiwidXBkYXRlZEluVmVyIjoiNDEuODIuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUmVub3ZhdGUgQm90Il19-->
BagToad
added a commit
that referenced
this pull request
Nov 6, 2025
|
SamMorrowDrums
added a commit
to github/github-mcp-server
that referenced
this pull request
Dec 12, 2025
- license-check.yml: Auto-regenerate licenses, push fix to PR, and comment - script/licenses: Pin go-licenses version in CI for reproducibility - script/licenses-check: Pin go-licenses version in CI - code-scanning.yml: Exclude third-party folder from CodeQL Inspired by cli/cli improvements: - cli/cli#11161 (pinned version) - cli/cli#11127 (GHAS exclusion) - cli/cli#11370 (auto-regenerate)
SamMorrowDrums
added a commit
to github/github-mcp-server
that referenced
this pull request
Dec 12, 2025
- license-check.yml: Auto-regenerate licenses, push fix to PR, and comment - script/licenses: Pin go-licenses version in CI for reproducibility - script/licenses-check: Pin go-licenses version in CI - code-scanning.yml: Exclude third-party folder from CodeQL Inspired by cli/cli improvements: - cli/cli#11161 (pinned version) - cli/cli#11127 (GHAS exclusion) - cli/cli#11370 (auto-regenerate)
SamMorrowDrums
added a commit
to github/github-mcp-server
that referenced
this pull request
Dec 12, 2025
- license-check.yml: Auto-regenerate licenses, push fix to PR, and comment - script/licenses: Pin go-licenses version in CI for reproducibility - script/licenses-check: Pin go-licenses version in CI - code-scanning.yml: Exclude third-party folder from CodeQL Inspired by cli/cli improvements: - cli/cli#11161 (pinned version) - cli/cli#11127 (GHAS exclusion) - cli/cli#11370 (auto-regenerate)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #11270
This commit refactors the work done in #11047 of blocking pull requests for manual
third-partylicense updates to having GitHub Actions automatically update it on pushes totrunk.This will allow maintainers to streamline Dependabot PR reviews while reducing contributor friction when changing dependencies.
Demo
Demonstrating running GitHub Actions workflow that is canceled by newer workflow run
Demonstrating multiple GitHub Actions workflows being canceled by newer workflow run
Demonstrating updates to third-party license documentation