Skip to content

fix(ci): SHA-pin Core reusable workflows previously at @v2 - #97

Closed
cryptoxdog wants to merge 1 commit into
mainfrom
agent/cursor/issue-112-lr
Closed

cryptoxdog wants to merge 1 commit into
mainfrom
agent/cursor/issue-112-lr

Conversation

@cryptoxdog

Copy link
Copy Markdown
Collaborator

Problem

fix(ci): SHA-pin Core reusable workflows previously at @v2

Closes #112

Fix

fix(ci): SHA-pin Core reusable workflows previously at @v2

Risk

  • Low — additive, reversible, no data or contract change — n/a — not this change
  • Medium — touches shared code, config, or a public interface
  • High — breaking change, migration, IAM/network, or irreversible — n/a — not this change

Blast radius: measured paths in Changes by intent
Rollback: revert this PR

Evidence

gate-receipt.json present: schema=l9.pr_gate_receipt.v2 content_digest=1172403212 passed_at=2026-09-20T03:18:46Z
L4 receipt present: phase=release_authorized tree_digest=cc29acabf11b6c05af0d3926cc3bf9241c8232b513cbe71e06e10f7663e49dbe kernel_evidence=evidenced

Gates

  • Regression test added that fails without this fix — n/a — not this change
  • No secrets, tokens, or customer data in code, tests, fixtures, or logs
  • semgrep clean, or findings triaged below — n/a — not this change
  • New IAM / workflow permissions are least privilege and enumerated — n/a — not this change
  • Third-party actions pinned to a full commit SHA — n/a — not this change
  • Public interface change is documented and versioned — n/a — not this change
  • Observability exists for the new path (metric, log, trace, or alert) — n/a — not this change

Reviewer focus

See Changes by intent and Protected-root (if any additive_only path).

Changes by intent

Added

  • n/a

Modified

  • .github/workflows/l9-governance.yml — fix(ci): SHA-pin Core reusable workflows previously at @v2
  • .github/workflows/l9-pre-commit.yml — fix(ci): SHA-pin Core reusable workflows previously at @v2
  • .github/workflows/l9-sbom.yml — fix(ci): SHA-pin Core reusable workflows previously at @v2
  • .github/workflows/l9-scorecard.yml — fix(ci): SHA-pin Core reusable workflows previously at @v2
  • .github/workflows/l9-security.yml — fix(ci): SHA-pin Core reusable workflows previously at @v2

Deleted

  • n/a

Files touched

  • M .github/workflows/l9-governance.yml
  • M .github/workflows/l9-pre-commit.yml
  • M .github/workflows/l9-sbom.yml
  • M .github/workflows/l9-scorecard.yml
  • M .github/workflows/l9-security.yml

Commits

  • fix(ci): SHA-pin Core reusable workflows previously at @v2

Test plan

  • make pr local gate receipt present
  • L4 release receipt present (release_authorized)
  • CI green — not measured by open_pr_after_gate.sh — do not treat as verified

Changed files

  • M .github/workflows/l9-governance.yml
  • M .github/workflows/l9-pre-commit.yml
  • M .github/workflows/l9-sbom.yml
  • M .github/workflows/l9-scorecard.yml
  • M .github/workflows/l9-security.yml

Issue-Remediation-Cycle: Quantum-L9/.github#112/cycle-1
Co-authored-by: Cursor <cursoragent@cursor.com>
Copilot AI lite review requested due to automatic review settings September 20, 2026 03:18
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-20T03:21:46.213998Z b44680d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sonarqubecloud

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The changes are limited to deterministic SHA-pinning of reusable workflows and appear syntactically correct with no remaining @v2 references.

Review effort: Lite
Findings: None

What changed in this PR

This PR hardens the repository’s CI configuration by replacing @v2 references to the Quantum-L9/l9-ci-core reusable workflows with a full commit SHA, ensuring workflow execution is pinned to an immutable revision.

Changes:

  • Replaced uses: ...@v2 with uses: ...@450f6ec753435365c6e4212cc898ee9ba560bb7d across the L9 workflow entrypoints.
  • Kept an inline # v2 annotation to indicate the pinned SHA corresponds to the previously used v2 reference.
File Description
.github/​workflows/​l9-governance.yml Pins governance reusable workflow reference to a full commit SHA.
.github/​workflows/​l9-pre-commit.yml Pins pre-commit reusable workflow reference to a full commit SHA.
.github/​workflows/​l9-sbom.yml Pins SBOM reusable workflow reference to a full commit SHA.
.github/​workflows/​l9-scorecard.yml Pins Scorecard reusable workflow reference to a full commit SHA.
.github/​workflows/​l9-security.yml Pins security reusable workflow reference to a full commit SHA.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cryptoxdog

Copy link
Copy Markdown
Collaborator Author

Closing without merge. This PR replaced intentional Core @v2 moving-major pins with immutable SHAs. Org policy is major version tags (@v1 / @v2), not SHA pins. The @v2 callers on main stay as they were.

@cryptoxdog cryptoxdog closed this Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants