Skip to content

ci: pin Diagnostics checkout + checksum bazelisk on Diagnostics and Binding RC #473

Description

@DecisionNerd

Summary

bazel-diagnostics still uses a floating actions/checkout@v7 tag and an unchecked curl | chmod +x bazelisk install. Binding RC Linux Bazel lanes (python + node) use the same unchecked bazelisk install. Required bazel-bootstrap already pins checkout and verifies bazelisk SHA-256; these surfaces must match.

Acceptance criteria

  • bazel-diagnostics checkout pinned to the same SHA as bootstrap (actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1)
  • bazel-diagnostics Install Bazelisk uses checksum + shasum --check + sudo install -m 0755 (no bare chmod +x)
  • Binding RC python and node Bazel lanes use the same checksum install pattern (linux-amd64)
  • Binding RC contract test comment updated if it still claims bazelisk uses chmod +x
  • Existing chmod-forbidding contract assertions still pass

Non-goals

  • npm trusted publisher / token deletion
  • Suite-membership gate relocation (separate issue)
  • Classifier arm ordering
  • Job timeouts

Source

Devinfra Audit Recheck Wave E / PR-B

Validation

  • python3 scripts/ci/test-ci-storage-policy.py
  • python3 scripts/ci/test-binding-release-candidate.py

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions