fix(ci): pin standards reusables to default-branch HEAD - #88
Conversation
This repo's standards reusable pins are re-pointed at the standards default-branch HEAD, resolved live at sweep time. The prior refs are recorded in the verification line below. Three kinds of drift are repaired together and the body does not claim which one this repo had: an UNREACHABLE sha kills the run at workflow STARTUP, so GitHub reports no check at all rather than a failing one and the gate disappears instead of going red; a FLOATING ref (@main) is unpinned supply chain; a merely STALE but reachable sha silently reintroduces every bug fixed since it. files=5 pins=5 perms=0 permlines=0 from=5b1d00229e5e8c0c0fbfedc7e80f37ea50f49236,81dbf2dd854b1444fd6236fa2352474383b2c2b9,c65436ee3351cd6b0fa14b142938b195efc77586,d135b05bfc647d0c0fbfedc7e80f37ea50f49236 target=8f2ee508 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0178nN4Nm3neFRy5K9StZKnB
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (5)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (24)
🔇 Additional comments (5)
📝 SummarySummary by CodeRabbit
WalkthroughFive GitHub Actions workflows now reference updated pinned commits for reusable governance, scanning, mirroring, scorecard, and secret-scanning workflows. ChangesReusable workflow pin updates
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to The governance, scanning, mirroring, scorecard, and secret-scanning workflows now use a consistent immutable standards revision without changing their permissions or configuration. No current merge-blocking risk is identified. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks each workflow pin Comment |
|



Re-points this repo's
hyperpolymath/standardsreusable-workflow pins at the standards default-branch HEAD,8f2ee50841e216cd8c192eeb68953118190f105c.Why this is not a routine version bump.
uses: org/repo/.github/workflows/x.yml@<ref>is resolved at workflow startup, so a bad ref is not a failing job — it is no job at all. This campaign repairs three kinds of drift and does not assume which one this repo had:gh pr checkssimply lists fewer rows. A repo in this state looks greener than one with working gates;@mainruns, but unpinned — the supply-chain property the estate pins for is absent;The refs this repo was actually pinned to, before this PR:
5b1d00229e5e8c0c0fbfedc7e80f37ea50f49236 81dbf2dd854b1444fd6236fa2352474383b2c2b9 c65436ee3351cd6b0fa14b142938b195efc77586 d135b05bfc647d0c0fbfedc7e80f37ea50f49236.Expect this PR to surface failures that main does not show. Those failures are revealed, not introduced — they are the gates resuming work after being silently absent. The honest comparison is the set of check names emitted here versus on
main, not pass/fail counts. On the canary (hyperpolymath/empty-linter#79) the governance suite was absent on main and emitted 25 checks once repaired.The target is default-branch HEAD resolved at sweep time, never a sha copied from a plan: a reachable but non-HEAD sha silently reintroduces every bug fixed since it.
Engine:
.git-private-farm/scripts/smtp-notify-sweep.sh --campaign campaigns/pin-repair.sh. Verification for this repo:files=5 pins=5 perms=0 permlines=0 from=5b1d00229e5e8c0c0fbfedc7e80f37ea50f49236,81dbf2dd854b1444fd6236fa2352474383b2c2b9,c65436ee3351cd6b0fa14b142938b195efc77586,d135b05bfc647d0c0fbfedc7e80f37ea50f49236 target=8f2ee508 sig=G 775ac79 canon=a7325fbdc356 base=main🤖 Generated with Claude Code
https://claude.ai/code/session_0178nN4Nm3neFRy5K9StZKnB