Summary
bazel-diagnostics still uses a floating actions/checkout@v7 tag and an unchecked curl | chmod +x bazelisk install. Binding RC Linux Bazel lanes (python + node) use the same unchecked bazelisk install. Required bazel-bootstrap already pins checkout and verifies bazelisk SHA-256; these surfaces must match.
Acceptance criteria
Non-goals
- npm trusted publisher / token deletion
- Suite-membership gate relocation (separate issue)
- Classifier arm ordering
- Job timeouts
Source
Devinfra Audit Recheck Wave E / PR-B
Validation
python3 scripts/ci/test-ci-storage-policy.py
python3 scripts/ci/test-binding-release-candidate.py
Summary
bazel-diagnosticsstill uses a floatingactions/checkout@v7tag and an uncheckedcurl | chmod +xbazelisk install. Binding RC Linux Bazel lanes (python + node) use the same unchecked bazelisk install. Requiredbazel-bootstrapalready pins checkout and verifies bazelisk SHA-256; these surfaces must match.Acceptance criteria
bazel-diagnosticscheckout pinned to the same SHA as bootstrap (actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1)bazel-diagnosticsInstall Bazelisk uses checksum +shasum --check+sudo install -m 0755(no barechmod +x)chmod +xNon-goals
Source
Devinfra Audit Recheck Wave E / PR-B
Validation
python3 scripts/ci/test-ci-storage-policy.pypython3 scripts/ci/test-binding-release-candidate.py