Skip to content

ci: pin ci-workflows composites to v0.39.8 - #462

Merged
kyle-sexton merged 2 commits into
mainfrom
ci/repin-v0.39.8
Oct 10, 2026
Merged

kyle-sexton merged 2 commits into
mainfrom
ci/repin-v0.39.8

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Related

Refs: melodic-software/ci-workflows#726

Fix

Moves every non-synced ci-workflows reference (composites and reusables) and the release/dependencies.json pin to v0.39.8, which fixes the aggregate-results race that could leave a contract-only ci-status run red.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt

Move every non-synced ci-workflows reference, composites and reusables,
to v0.39.8 and update release/dependencies.json to match, as the
one-SHA pin governance requires.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt
@github-actions

Copy link
Copy Markdown

PR body contract — issue linkage

This PR body does not yet satisfy the issue-linkage contract:

  • Missing a "## Summary" section. Describe what this PR changes and why, in a sentence or two.
  • Missing a "## Verification" section. Record concrete evidence the change works (commands, gates, output).

Edit the body and this comment updates itself on the next run.

@kyle-sexton
kyle-sexton marked this pull request as ready for review October 10, 2026 22:14
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T22:17:00.067102Z 39a2887 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 48s —— View job


Security review — no issues found

  • Gather context (PR diff, changed files)
  • Review changed files for security-relevant issues
  • Check for instruction-surface deletions
  • Report findings

Scope: This PR touches only three files — pr-automerge-dependabot.yml, pr-require-checks.yml, and release/dependencies.json — and is a mechanical re-pin of every melodic-software/ci-workflows composite/reusable reference (and the matching repositoryPins entry) from the v0.39.3 commit SHA to the v0.39.8 commit SHA. No workflow logic, trigger, permission, or with: input changed; every reference remains full-length-SHA pinned (never loosened to a tag/branch), so there's no new injection, privilege, or supply-chain-pinning surface for this lane to flag — SHA-pin loosening/unpinning is zizmor's advisory lane per this skill's scope, and that's not what happened here anyway since both old and new refs are full commit SHAs.

No instruction files (CLAUDE.md, AGENTS.md, rules files, hooks) are touched, so the instruction-surface-deletion check doesn't apply.

Result: no security findings. This is a low-risk, logic-free version bump.
· branch ci/repin-v0.39.8

@claude

claude Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 2m 4s —— View job


Code review — PR #462

  • Gather context (diff, changed files)
  • Understand request (invoke /review:code-review)
  • Review changed files for correctness/maintainability
  • Post findings (inline + summary)

Scope: .github/workflows/pr-automerge-dependabot.yml, .github/workflows/pr-require-checks.yml, release/dependencies.json — a mechanical re-pin of every non-SYNC-MANAGED melodic-software/ci-workflows reference from ab83b01 (v0.39.3) to 594987a (v0.39.8), plus the matching release/dependencies.json repository pin.

Findings: none that meet this lane's high-signal bar.

What I checked:

  • Repo-wide grep for melodic-software/ci-workflows confirms every canonical (non-SYNC-MANAGED) uses: line — in pr-require-checks.yml and pr-automerge-dependabot.yml — now agrees on one SHA (594987abe8657a40bccc13d301f1f0d5cccb5348) and one version comment (v0.39.8), consistent with the "one reviewed compatibility pin" invariant enforced by .github/scripts/workflow-pin-metadata.test.cjs.
  • Three hosted workflows still carry the old ab83b01… / v0.39.3 reference — pr-check-managed-files-hosted.yml#L106, pr-review-hosted.yml#L83, pr-review-security-hosted.yml#L84. This looked like a gap at first, but all three are SYNC-MANAGED FILE callers owned by melodic-software/standards; both the node test (advisoryReference/syncManagedMarker branch) and scripts/Test-ReleasePins.ps1 (lines ~355-369) explicitly exempt SYNC-MANAGED ci-workflows references from this repo's compatibility-pin inventory, so leaving them untouched is correct, not an omission.
  • release/dependencies.json's repositoryPins entry for melodic-software/ci-workflows moves to the same SHA, matching the ciWorkflowsPin() cross-check in the node test.
  • Diff is otherwise a pure SHA/version-comment substitution with no structural or logic changes.

Not independently verified (author-claimed): that v0.39.8 actually fixes the described aggregate-results race in ci-workflows, and that 594987abe8657a40bccc13d301f1f0d5cccb5348 is the correct commit for the v0.39.8 tag — I don't have authenticated access to melodic-software/ci-workflows from this sandbox to confirm against the upstream tag/release.

Separately, the automated pr-contract comment already flags the PR body as missing ## Summary and ## Verification sections per the PR body contract — worth filling in before merge, though that's an advisory lane, not this review's concern.
· branch ci/repin-v0.39.8

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

claude-security-review has reviewed this pull request through 39a2887; a later push is reviewed from there.

@github-actions

Copy link
Copy Markdown

claude-review has reviewed this pull request through 39a2887; a later push is reviewed from there.

@kyle-sexton
kyle-sexton merged commit 3fa0ba6 into main Oct 10, 2026
28 checks passed
@kyle-sexton
kyle-sexton deleted the ci/repin-v0.39.8 branch October 10, 2026 22:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant