Skip to content

ci: pin Diagnostics checkout + checksum bazelisk - #477

Merged
DecisionNerd merged 1 commit into
mainfrom
ci/473-pin-diagnostics-checksum-bazelisk
Aug 7, 2026
Merged

DecisionNerd merged 1 commit into
mainfrom
ci/473-pin-diagnostics-checksum-bazelisk

Conversation

@DecisionNerd

@DecisionNerd DecisionNerd commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Pin bazel-diagnostics actions/checkout to the same SHA as bootstrap
  • Verify bazelisk SHA-256 on Diagnostics and Binding RC Linux Bazel lanes
  • Refresh Binding RC contract comment for the install pattern

Test plan

  • python3 scripts/ci/test-ci-storage-policy.py
  • python3 scripts/ci/test-binding-release-candidate.py
  • CI Gate green on this head

Fixes #473

Made with Cursor


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Note

Pin Diagnostics checkout and add checksum verification for Bazelisk install in CI

  • Pins the actions/checkout step in the bazel-diagnostics job to a specific commit SHA (v7.0.1) instead of the floating @v7 tag.
  • Replaces the direct curl-and-chmod Bazelisk install with a verified install: downloads to a temp path, checks a hardcoded SHA-256 for v1.26.0, then installs with sudo install -m 0755. Applied to all affected CI jobs in binding-release-candidate.yml and test.yml.
  • Behavioral Change: CI jobs now fail if the Bazelisk binary checksum does not match, rather than silently proceeding with an unverified binary.

Macroscope summarized 298e8ea.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 59 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 13268661-439b-4ba2-ab90-25b1cc06b3e6

📥 Commits

Reviewing files that changed from the base of the PR and between c983b03 and 298e8ea.

⛔ Files ignored due to path filters (2)
  • .github/workflows/binding-release-candidate.yml is excluded by !**/.github/**
  • .github/workflows/test.yml is excluded by !**/.github/**
📒 Files selected for processing (1)
  • scripts/ci/test-binding-release-candidate.py

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added ci-cd CI/CD configuration changes tooling Developer tooling and automation release:none No release note or version impact labels Aug 7, 2026
Match bazel-bootstrap supply-chain hygiene on the diagnostic lane and
Binding RC Linux Bazel builders.

Fixes #473

Co-authored-by: Cursor <cursoragent@cursor.com>
@DecisionNerd
DecisionNerd force-pushed the ci/473-pin-diagnostics-checksum-bazelisk branch from 195d413 to 298e8ea Compare August 7, 2026 19:51
@DecisionNerd
DecisionNerd merged commit 5db4fd5 into main Aug 7, 2026
19 checks passed
@DecisionNerd
DecisionNerd deleted the ci/473-pin-diagnostics-checksum-bazelisk branch August 13, 2026 02:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-cd CI/CD configuration changes release:none No release note or version impact tooling Developer tooling and automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: pin Diagnostics checkout + checksum bazelisk on Diagnostics and Binding RC

1 participant