diff --git a/.editorconfig-checker.json b/.editorconfig-checker.json index 1a8d8fe..671bee9 100644 --- a/.editorconfig-checker.json +++ b/.editorconfig-checker.json @@ -1,5 +1,5 @@ { - "_comment": "Root-canonical editorconfig-checker policy (keys per editorconfig-checker 3.x). Validates files against the repo-root .editorconfig. Line endings are NOT checked here: .gitattributes is the single authority for EOL, so EndOfLine is disabled to avoid double-enforcement. IndentSize and MaxLineLength are disabled because indent width and line length are owned by per-language formatters and are IDE hints, not hard rules. Only deviations from the engine defaults are listed. Verbose, Debug, IgnoreDefaults, SpacesAfterTabs, NoColor, AllowedContentTypes, PassedFiles, and the Disable entries not named below already hold their engine defaults, so they are omitted deliberately rather than restated; do not add them back. Note AllowedContentTypes is omitted rather than left empty because the engine merges a non-empty value onto its defaults and skips an empty one, so `[]` was already a no-op. Exclude[] entries are universal regular expressions; managed consumers do not edit this file and pass repository-specific excludes with -exclude (which combines additively). Version is intentionally blank so the config adopts cleanly on any 3.x engine; consumers pin the engine in CI.", + "_comment": "Root-canonical editorconfig-checker policy (keys per editorconfig-checker 4.x). Validates files against the repo-root .editorconfig. Line endings are NOT checked here: .gitattributes is the single authority for EOL, so EndOfLine is disabled to avoid double-enforcement. IndentSize and MaxLineLength are disabled because indent width and line length are owned by per-language formatters and are IDE hints, not hard rules. Only deviations from the engine defaults are listed. Verbose, Debug, IgnoreDefaults, NoColor, AllowedContentTypes, PassedFiles, and the Disable entries not named below already hold their engine defaults, so they are omitted deliberately rather than restated; do not add them back. Note AllowedContentTypes is omitted rather than left empty because the engine merges a non-empty value onto its defaults and skips an empty one, so `[]` was already a no-op. Exclude[] entries are universal regular expressions; managed consumers do not edit this file and pass repository-specific excludes with -exclude (which combines additively). Version is intentionally blank so the config adopts cleanly on any 4.x engine; consumers pin the engine in CI.", "Version": "", "Exclude": [ "bin/", diff --git a/.github/workflows/claude-review-hosted.yml b/.github/workflows/claude-review-hosted.yml index e89ff9b..8418c6e 100644 --- a/.github/workflows/claude-review-hosted.yml +++ b/.github/workflows/claude-review-hosted.yml @@ -85,7 +85,7 @@ jobs: concurrency: group: claude-review-${{ github.repository }} queue: max - uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@0d3e6a6f3851cf678f82fa9a8a17f10faa909ac9 # v0.29.1 + uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@35880dcbb2f174aac90159e276dc7eddf1bc20b9 # v0.30.1 with: runner: ubuntu-24.04 # Pass only the one named secret (least privilege) rather than diff --git a/.github/workflows/claude-security-review-hosted.yml b/.github/workflows/claude-security-review-hosted.yml index a927d41..6e7bed6 100644 --- a/.github/workflows/claude-security-review-hosted.yml +++ b/.github/workflows/claude-security-review-hosted.yml @@ -76,7 +76,7 @@ jobs: concurrency: group: claude-security-review-${{ github.event.pull_request.number || github.run_id }} cancel-in-progress: false - uses: melodic-software/ci-workflows/.github/workflows/claude-security-review.yml@0d3e6a6f3851cf678f82fa9a8a17f10faa909ac9 # v0.29.1 + uses: melodic-software/ci-workflows/.github/workflows/claude-security-review.yml@35880dcbb2f174aac90159e276dc7eddf1bc20b9 # v0.30.1 with: runner: ubuntu-24.04 # Pass only the one named secret (least privilege) rather than