Skip to content

ci(workspace): enforce pinned workflow policy - #66

Merged
francoischalifour merged 2 commits into
altertable-ai:mainfrom
albert20260301:chore/rename-semantic-pull-request
Aug 3, 2026
Merged

francoischalifour merged 2 commits into
altertable-ai:mainfrom
albert20260301:chore/rename-semantic-pull-request

Conversation

@albert20260301

@albert20260301 albert20260301 commented Aug 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • rename the managed semantic-title workflow to .github/workflows/semantic-pull-request.yml
  • standardize workspace and managed Linux jobs on the GitHub-hosted ubuntu-24.04 LTS image
  • pin every external workspace/managed workflow action to an immutable commit SHA, with its reviewed release version recorded in a comment
  • add scripts/validate-workflow-policy.sh to audit all workflow files for runner/action drift and Node/Bun runtime-file usage
  • require Node workflows to use root .node-version via node-version-file, and Bun workflows to use root .bun-version via bun-version-file

Impact

PR #66 is now the canonical policy and enforcement point. sdk-sync will audit every repository-owned workflow and open focused follow-up PRs for drift; it preserves each repository's supported Node/Bun versions rather than imposing a shared version.

Validation

  • bash -n scripts/validate-workflow-policy.sh scripts/validate-workspace.sh
  • bash scripts/validate-workflow-policy.sh .
  • bash scripts/validate-workspace.sh
  • make lint
  • git diff --check
  • negative checks confirmed the audit rejects current ubuntu-latest and hard-coded Bun-version drift in local SDK checkouts
  • GitHub action tags resolved before pinning: actions/checkout v7.0.1, lycheeverse/lychee-action v2.9.0, amannn/action-semantic-pull-request v6.1.1

@albert20260301

Copy link
Copy Markdown
Contributor Author

@francoischalifour could you review this?

I picked you because you requested this workflow standardization. CI is green. The main review focus is that the renamed managed file exactly matches the pinned CLI workflow and rejects future floating action or runner versions.

@albert20260301 albert20260301 changed the title chore(workspace): pin semantic PR workflow ci(workspace): enforce pinned workflow policy Aug 3, 2026
@albert20260301

Copy link
Copy Markdown
Contributor Author

@francoischalifour PR #66 has been repurposed and is green. It now enforces ubuntu-24.04, immutable action SHAs, and .node-version/.bun-version consumption for Node/Bun workflows, with a reusable audit for SDK sync.

@francoischalifour
francoischalifour merged commit 2dd0719 into altertable-ai:main Aug 3, 2026
2 checks passed
@albert20260301
albert20260301 deleted the chore/rename-semantic-pull-request branch August 3, 2026 12:36
@albert20260301
albert20260301 restored the chore/rename-semantic-pull-request branch August 3, 2026 12:36
@albert20260301
albert20260301 deleted the chore/rename-semantic-pull-request branch August 3, 2026 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants