# Run Danger on its dedicated Namespace profile \(\#64632\) · gitcafe/zed

[View on GitCafe](https://git.cafe/gitcafe/zed/commit/fbb313eb33cdd435996b34ab3e8c84ebc66f6a7f)

Repository: [gitcafe/zed](https://git.cafe/gitcafe/zed)

Visibility: public

Requested revision: fbb313eb33cdd435996b34ab3e8c84ebc66f6a7f

Requested commit: fbb313eb33cdd435996b34ab3e8c84ebc66f6a7f

Commit: fbb313eb33cdd435996b34ab3e8c84ebc66f6a7f

Tree: 420db678b84d7d4ab6a091f926d4576371345c2e

Author: Conrad Irwin

Committer: GitHub

## Message

```
Run Danger on its dedicated Namespace profile (#64632)

## Summary

Run Danger on the preconfigured `namespace-profile-dangerbot` runner
instead of the shared `namespace-profile-2x4-ubuntu-2404` profile. The
dedicated profile lets Namespace inject the Danger proxy credential
through its egress policy without enabling that capability for unrelated
jobs on the shared profile.

Update the Rust workflow generator, generated workflow, and actionlint
runner-label allowlist together. The proxy URL and placeholder GitHub
token remain unchanged. Proxy-side secret validation is a separate
follow-up; this PR only switches the runner profile.

## Validation

- `cargo fmt --package xtask -- --check`
- `cargo xtask workflows` (including generated workflow validation)
- `actionlint -oneline .github/workflows/danger.yml` (v1.7.12)
- `git diff --check`
- Confirmed the `dangerbot` Namespace profile exists with Ubuntu 24.04,
2 CPUs, and 4 GiB RAM.

The first Danger run on this PR will exercise the new profile; local
checks do not verify runtime header injection.

Release Notes:

- N/A
```

## Parents

- [a39324bf99fff457ee605c37509603eb55b0faed](https://git.cafe/gitcafe/zed/commit/a39324bf99fff457ee605c37509603eb55b0faed?format=markdown)

[Source at this commit](https://git.cafe/gitcafe/zed/tree/fbb313eb33cdd435996b34ab3e8c84ebc66f6a7f?format=markdown)
