diff --git a/.github/workflows/bootstrap-common-workflows.yml b/.github/workflows/bootstrap-common-workflows.yml index 9c9c6c1..feb31e9 100644 --- a/.github/workflows/bootstrap-common-workflows.yml +++ b/.github/workflows/bootstrap-common-workflows.yml @@ -44,7 +44,10 @@ env: # Chronicle.Dapr - its own publication-boundary governance (tools/verify-workflow-boundary.py) # declares exactly build, preview-publish, and the pinned verify-no-work-records; # the bootstrap's wrappers and wrapper rewrites violate it - REPOS_TO_IGNORE: '["Workflows","cratis.github.io","StudioIssues","Documentation","cratis.studio","Automation",".github","Dockerfiles","AI","Templates","Dockerfiles","release-action","Chronicle.Dapr"]' + # Chronicle.Wolverine - its reviewed workflow composition (test_reviewed_workflow_composition.py) + # requires full-SHA pins, the declared secret only, extra-allowed VERSIONS, and the + # manual reviewed-update path; the bootstrap's @main rewrites violate it + REPOS_TO_IGNORE: '["Workflows","cratis.github.io","StudioIssues","Documentation","cratis.studio","Automation",".github","Dockerfiles","AI","Templates","Dockerfiles","release-action","Chronicle.Dapr","Chronicle.Wolverine"]' jobs: bootstrap: