ci(issue-triage-label): record why the reusable stays on ci-workflows v0.27.1 - #6141
Conversation
… v0.27.1 Co-authored-by: ksextonmelodic <ksextonmelodic@gmail.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 24s —— View job CI code review
Skip gate hit: this PR adds a 5-line comment above the Spot-checked the claim anyway: |
|
Claude finished @kyle-sexton's task in 32s —— View job Security review —
|
|
claude-review has reviewed this pull request through f07c55f; a later push is reviewed from there. |
|
claude-security-review has reviewed this pull request through f07c55f; a later push is reviewed from there. |
Summary
#5782 asked to move the last two ci-workflows v0.27.1 pins to
ci.yml's v0.30.2, or to record why either has to stay.test-windows.ymlno longer references ci-workflows (#5874, #6002, #6023 and #6129 removed the change-detection step), so onlyissue-triage-label.ymlis left. That pin has to stay for now, and the workflow now says why.Fix
uses:line in.github/workflows/issue-triage-label.ymlexplains that v0.27.1 is the newest SHA with a reviewed contract in.github/standards/runner-policy/policy.json. A repin waits on a reviewed contract for the new SHA inmelodic-software/standards.# v0.27.1version comment are unchanged.Verification
node .github/standards/runner-policy/runner-policy.mjs --root .fails withrunner-target-contract: the reusable workflow path@SHA has no reviewed runner-input contract (auto-approval declined: melodic-software/ci-workflows/.github/workflows/issue-triage-label.yml carries a reviewed allowedCallerPermissions grant ...). The gate never auto-approves a new SHA for a reusable that carries a caller-permission grant (issues: writehere); a person has to review it (runner-policy.mjs,resolveAutoApprovedContracts).policy.jsonholds reviewed contracts for this reusable at v0.22.0, v0.22.1, v0.22.2, v0.24.0, v0.27.0 and v0.27.1, plus one SHA with no release tag. None is newer than v0.27.1. The SHAs were matched to tags withgh api repos/melodic-software/ci-workflows/tags.gh api repos/melodic-software/ci-workflows/compare/4610c31e...a267a27f), so staying behind loses nothing.typosis clean.Related
Closes #5782