Skip to content

fix(relock): keep a tag key a workflow still writes (WIP, untested) - #1135

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/relock-keep-live-tag-keys
Oct 2, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
fix/relock-keep-live-tag-keys

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Re-keying actions/checkout@v7.0.1 to its SHA because ONE workflow pins the SHA inline strands the 17 workflows that still write the tag: prune-stale empties their lists and --verify-local reports not-pinned (metadatastician/_pathroot, 2026-10-02). Skip the re-key when the tag is still written on a live uses: line.

UNTESTED: the end-to-end run was cut off by an exhausted REST quota. Needs a known-answer test and a rerun on _pathroot before a PR is opened.

Claude-Session: https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

Re-keying actions/checkout@v7.0.1 to its SHA because ONE workflow pins the
SHA inline strands the 17 workflows that still write the tag: prune-stale
empties their lists and --verify-local reports not-pinned
(metadatastician/_pathroot, 2026-10-02). Skip the re-key when the tag is
still written on a live uses: line.

UNTESTED: the end-to-end run was cut off by an exhausted REST quota. Needs a
known-answer test and a rerun on _pathroot before a PR is opened.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 41 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 12c8fac9-861d-4ddb-92a6-006298a4612d

📥 Commits

Reviewing files that changed from the base of the PR and between aa8fd9e and 50ff55c.

📒 Files selected for processing (1)
  • scripts/relock-sha-keys.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 2, 2026 01:25
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

@hyperpolymath
hyperpolymath merged commit f5f48a4 into main Oct 2, 2026
48 checks passed
@hyperpolymath
hyperpolymath deleted the fix/relock-keep-live-tag-keys branch October 2, 2026 01:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant