Skip to content

ci(issue-triage-label): record why the reusable stays on ci-workflows v0.27.1 - #6141

Merged
cursor[bot] merged 1 commit into
mainfrom
cursor/ci-triage-label-pin-e44b
Oct 4, 2026
Merged

cursor[bot] merged 1 commit into
mainfrom
cursor/ci-triage-label-pin-e44b

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Summary

#5782 asked to move the last two ci-workflows v0.27.1 pins to ci.yml's v0.30.2, or to record why either has to stay. test-windows.yml no longer references ci-workflows (#5874, #6002, #6023 and #6129 removed the change-detection step), so only issue-triage-label.yml is left. That pin has to stay for now, and the workflow now says why.

Fix

  • A comment above the uses: line in .github/workflows/issue-triage-label.yml explains that v0.27.1 is the newest SHA with a reviewed contract in .github/standards/runner-policy/policy.json. A repin waits on a reviewed contract for the new SHA in melodic-software/standards.
  • The pin and its # v0.27.1 version comment are unchanged.

Verification

  • The repin was tried first. node .github/standards/runner-policy/runner-policy.mjs --root . fails with runner-target-contract: the reusable workflow path@SHA has no reviewed runner-input contract (auto-approval declined: melodic-software/ci-workflows/.github/workflows/issue-triage-label.yml carries a reviewed allowedCallerPermissions grant ...). The gate never auto-approves a new SHA for a reusable that carries a caller-permission grant (issues: write here); a person has to review it (runner-policy.mjs, resolveAutoApprovedContracts).
  • policy.json holds reviewed contracts for this reusable at v0.22.0, v0.22.1, v0.22.2, v0.24.0, v0.27.0 and v0.27.1, plus one SHA with no release tag. None is newer than v0.27.1. The SHAs were matched to tags with gh api repos/melodic-software/ci-workflows/tags.
  • The reusable changed only in comments between v0.27.1 and v0.30.2 (gh api repos/melodic-software/ci-workflows/compare/4610c31e...a267a27f), so staying behind loses nothing.
  • With this change, the runner-policy check passes, the YAML parses, and typos is clean.

Related

Closes #5782

Open in Web Open in Cursor 

… v0.27.1

Co-authored-by: ksextonmelodic <ksextonmelodic@gmail.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review October 4, 2026 01:22
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T01:23:37.843284Z f07c55f Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 24s —— View job


CI code review

  • Gather context (diff, .github/standards/runner-policy/policy.json)
  • Review against lane criteria
  • Post result

Skip gate hit: this PR adds a 5-line comment above the uses: line in .github/workflows/issue-triage-label.yml; no behavior, pin, or logic changes. Trivial/automated change with no meaningful review surface for this lane.

Spot-checked the claim anyway: .github/standards/runner-policy/policy.json:929 does hold a reviewed contract keyed to ...issue-triage-label.yml@4610c31e92eb1c4b24981e2f200ac87bdb2a1753, the SHA already pinned (and unchanged) in the workflow — matches the comment's claim that v0.27.1 is the newest SHA with a reviewed contract. No findings.

@claude

claude Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 32s —— View job


Security review — /review:security-review

  • Gather context (PR diff, changed files)
  • Run /review:security-review for this PR
  • Post findings

Result: no security issues — skip gate applied.

The entire diff is a 5-line comment addition above the existing uses: line in
.github/workflows/issue-triage-label.yml.
It explains why the pin stays on v0.27.1. No change to:

  • the SHA pin or version comment (4610c31e92eb1c4b24981e2f200ac87bdb2a1753 # v0.27.1, unchanged)
  • permissions: (issues: write, unchanged)
  • triggers, inputs, or any other workflow behavior

This is a pure documentation addition, not a removal or softening of a guardrail, so the
instruction-surface-deletion lens doesn't apply here — there's nothing being taken away for a
hostile context to exploit. No injection surface, no auth/access-control change, no secret
handling change. Nothing to report.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

claude-review has reviewed this pull request through f07c55f; a later push is reviewed from there.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

claude-security-review has reviewed this pull request through f07c55f; a later push is reviewed from there.

@cursor
cursor Bot added this pull request to the merge queue Oct 4, 2026
Merged via the queue into main with commit 38da2c2 Oct 4, 2026
37 of 38 checks passed
@cursor
cursor Bot deleted the cursor/ci-triage-label-pin-e44b branch October 4, 2026 01:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: test-windows.yml and issue-triage-label.yml still pin ci-workflows v0.27.1

2 participants