Skip to content

ci: pin ci-workflows composites to v0.39.8 - #85

Merged
kyle-sexton merged 2 commits into
mainfrom
ci/repin-v0.39.8
Oct 10, 2026
Merged

kyle-sexton merged 2 commits into
mainfrom
ci/repin-v0.39.8

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Related

Refs: melodic-software/ci-workflows#726

Fix

Pins the ci-workflows composites in pr-require-checks.yml to v0.39.8, which fixes the aggregate-results race that could leave a contract-only ci-status run red after the full run went green.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt
@github-actions

Copy link
Copy Markdown

PR body contract — issue linkage

This PR body does not yet satisfy the issue-linkage contract:

  • Missing a "## Summary" section. Describe what this PR changes and why, in a sentence or two.
  • Missing a "## Verification" section. Record concrete evidence the change works (commands, gates, output).

Edit the body and this comment updates itself on the next run.

@kyle-sexton
kyle-sexton marked this pull request as ready for review October 10, 2026 22:05
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T22:07:09.367021Z 919b9d4 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 10, 2026

Copy link
Copy Markdown

Claude Code is working…

I'll analyze this and get back to you.

View job run

@claude

claude Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 42s —— View job


Security review (/review:security-review)

  • Gather context (diff, workflow file, skill instructions)
  • Apply skip-gate / criteria from /review:security-review
  • Report result

Scope: .github/workflows/pr-require-checks.yml (+2/-2) — repins the check-contract and aggregate-results composite actions from melodic-software/ci-workflows from v0.39.3 to v0.39.8.

Finding: none.

Both references stay fully pinned to a 40-character commit SHA with a version-tag comment (ab83b01...a2 # v0.39.3 → 594987a...48 # v0.39.8); this is a version bump, not a loosening of the pin (unpinned tag/branch, shortened SHA, etc.), so it doesn't raise the supply-chain concern that lane would flag, and that class is zizmor's advisory lane regardless. No other logic, auth, injection, or secret-handling surface is touched in this diff. This is not a CLAUDE.md/AGENTS.md/rules-file change, so the instruction-surface-deletion lens doesn't apply.

No security issues found in this PR.

@claude

claude Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 1m 50s —— View job


Claude finished reviewing this PR

  • Gather context (diff, CLAUDE.md/AGENTS.md, REVIEW.md)
  • Review changed file for correctness/maintainability
  • Post findings

No findings.

This PR changes exactly two lines in .github/workflows/pr-require-checks.yml: the pinned SHA (and matching # v0.39.8 comment) for the check-contract and aggregate-results composite actions, bumped from v0.39.3. Both lines were updated together and consistently — same new SHA, same new version comment, no drift between the two.

Checked for related risk and found none:

  • Both pins point at the same melodic-software/ci-workflows commit, which is expected since both composites live in that one repo — consistent with the pre-existing pattern.
  • The third ci-workflows reference in the repo, pr-check-managed-files-hosted.yml:106, is still pinned to the old v0.39.3 SHA. That's not a gap: its adjacent comment documents it's deliberately pinned to the specific release that closed ci-workflows#530, independent of this PR's aggregate-results race fix — not something expected to track the other composites' version.
  • No logic in this repo changes; this is purely an upstream dependency pin bump with no other diff surface.

Unverified (no network access to the melodic-software/ci-workflows repo from this sandbox — gh api repos/melodic-software/ci-workflows/... required approval that wasn't available): that the new SHA 594987abe8657a40bccc13d301f1f0d5cccb5348 is in fact what the v0.39.8 tag in ci-workflows points to. This is author-claimed via the PR description and commit message, not something I independently confirmed.
·

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

claude-security-review has reviewed this pull request through bec3772; a later push is reviewed from there.

@github-actions

Copy link
Copy Markdown

claude-review has reviewed this pull request through bec3772; a later push is reviewed from there.

@kyle-sexton
kyle-sexton merged commit 60e468c into main Oct 10, 2026
7 checks passed
@kyle-sexton
kyle-sexton deleted the ci/repin-v0.39.8 branch October 10, 2026 22:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant