Skip to content

ci: pin ci-workflows composites to v0.39.8 - #102

Merged
kyle-sexton merged 2 commits into
mainfrom
ci/repin-v0.39.8
Oct 10, 2026
Merged

kyle-sexton merged 2 commits into
mainfrom
ci/repin-v0.39.8

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Related

Refs: melodic-software/ci-workflows#726

Fix

Pins the ci-workflows composites in pr-require-checks.yml to v0.39.8, which fixes the aggregate-results race that could leave a contract-only ci-status run red after the full run went green.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt
@github-actions

Copy link
Copy Markdown

PR body contract — issue linkage

This PR body does not yet satisfy the issue-linkage contract:

  • Missing a "## Summary" section. Describe what this PR changes and why, in a sentence or two.
  • Missing a "## Verification" section. Record concrete evidence the change works (commands, gates, output).

Edit the body and this comment updates itself on the next run.

@kyle-sexton
kyle-sexton marked this pull request as ready for review October 10, 2026 22:06
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TRhsMPSTMFo99ik7gkdgQt
@claude

claude Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 1m 10s —— View job


Security review (/review:security-review)

  • Gather context (PR diff, changed files)
  • Apply skip gate
  • Report result

Skip gate hit: no security-relevant surface.

This PR is a pure SHA-pin version bump in .github/workflows/pr-require-checks.yml: three melodic-software/ci-workflows composite action references move from the v0.39.3 commit SHA (ab83b01…) to the v0.39.8 commit SHA (594987a…):

  • typos action
  • pr-require-checks/check-contract action
  • pr-require-checks/aggregate-results action

Checked against this lane's criteria:

  • Pins stay fully pinned (full-length commit SHA both before and after) — not a loosened/unpinned supply-chain change, so no zizmor-lane finding to flag here either.
  • No permissions: or trigger changes — the diff touches only the uses: lines and their trailing version comments; job permissions: blocks are unchanged.
  • No new inputs, secrets, or trust-boundary changes — with: blocks for all three steps are unchanged.
  • No instruction-surface deletion — nothing removed from CLAUDE.md/AGENTS.md/workflow guardrails; the comment above the aggregate-results step (explaining the fallback-on-cancel behavior) is unchanged.

No logic, authorization, injection, or secret-handling surface is introduced or altered by this change. No findings.
·

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T22:07:56.047455Z 6f170b0 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 10, 2026

Copy link
Copy Markdown

Claude Code is working…

I'll analyze this and get back to you.

View job run

@claude

claude Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 1m 19s —— View job


Review: ci: pin ci-workflows composites to v0.39.8

  • Gather context (diff, CLAUDE.md/AGENTS.md, REVIEW.md criteria)
  • Understand the request (invoke /review:code-review per the triggering instructions)
  • Review the changed file
  • Report findings

Findings: none.

The diff is a mechanical pin bump in .github/workflows/pr-require-checks.yml: three melodic-software/ci-workflows composite-action references (typos, check-contract, aggregate-results) move from ab83b01… (v0.39.3) to 594987a… (v0.39.8), each with a matching SHA/version-comment pair. All three refs in the changed file land on the same new SHA, and the surrounding comments (contract-only predicate, !cancelled() rationale, treat-skipped-as: fail note) still accurately describe the code around them — nothing went stale from the bump. This matches the lane's skip gate for a trivial, no-meaningful-surface change, so no inline comments were posted.

Two notes, neither a blocking finding:

  • I could not independently verify 594987abe8657a40bccc13d301f1f0d5cccb5348 resolves to the v0.39.8 tag in melodic-software/ci-workflows — gh api and WebFetch both required interactive permission grants not available in this run. This is author-claimed/unverified by me, not confirmed.
  • Other workflow files in this repo (pr-review-hosted.yml, pr-review-security-hosted.yml, pr-automerge-dependabot.yml, pr-check-managed-files-hosted.yml) still pin ci-workflows at v0.39.3. That's outside this PR's changed files and the PR's stated scope (fixing the aggregate-results race in this one workflow), so not a finding — just flagging in case a follow-up re-pin is intended.

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

claude-security-review has reviewed this pull request through 46e867b; a later push is reviewed from there.

@github-actions

Copy link
Copy Markdown

claude-review has reviewed this pull request through 46e867b; a later push is reviewed from there.

@kyle-sexton
kyle-sexton merged commit e3371dc into main Oct 10, 2026
11 checks passed
@kyle-sexton
kyle-sexton deleted the ci/repin-v0.39.8 branch October 10, 2026 22:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant