Skip to content

Skip Chronicle.Wolverine in the common workflow bootstrap - #98

Merged
einari merged 1 commit into
mainfrom
fix/bootstrap-ignore-2
Sep 10, 2026
Merged

Skip Chronicle.Wolverine in the common workflow bootstrap#98
einari merged 1 commit into
mainfrom
fix/bootstrap-ignore-2

Conversation

@einari

@einari einari commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Companion to Chronicle.Wolverine#54: its reviewed workflow composition (workflow_security + reviewed_workflow_composition tests) requires pinned wrappers and a manual update path; the bootstrap's @main rewrites violate it. No release.

Chronicle.Wolverine's reviewed workflow composition requires full-SHA
pins, the declared secret only, extra-allowed VERSIONS, and a manual
reviewed package-update path. The bootstrap rewrites those wrappers to
unpinned @main calls and fails the repository's own workflow tests.
@einari
einari merged commit 39ea62b into main Sep 10, 2026
@einari
einari deleted the fix/bootstrap-ignore-2 branch September 10, 2026 12:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant