From the 2026-07-26 claude-review-lanes interview (decision record: .work/claude-review-lanes/interview-checklist.md, Brief: docs/topics/claude-review-lanes/PLAN.md).
Problem
Verified Dependabot mechanics: SHA-pinned actions never produce Dependabot security alerts ("Dependabot ... will not create alerts for actions pinned to SHA values"), and security updates are triggered by alerts — so for a SHA-pinning org, every security-relevant action bump arrives as an ordinary version update, subject to cooldown (a 3-day default applies since 2026-07-14 even with no cooldown block), grouping, and the open-PR budget. anthropics/claude-code-action gets a cooldown exemption in this effort; the rest of the fleet's pinned dependencies have not been audited for equivalent staleness/exposure.
Related real-world precedent: CVE-2026-47751 was delivered to floating-tag users automatically; SHA-pinned users needed their own bump.
Task
Fleet-wide audit (subagent team run is fine) across all melodic-software repos:
- Inventory every SHA-pinned
uses: (actions + reusable workflows) and every in-workflow tool-version constant invisible to Dependabot (the tool-version-drift-check.yml class).
- For each: current pin age vs upstream latest; whether Dependabot/renovate covers it; cooldown/grouping delay it is subject to; whether it is security-sensitive (token handling, runs on privileged triggers).
- Output: per-repo findings + recommended cooldown exemptions / drift-check additions; wire into the standards conventions where a policy is warranted.
From the 2026-07-26 claude-review-lanes interview (decision record:
.work/claude-review-lanes/interview-checklist.md, Brief:docs/topics/claude-review-lanes/PLAN.md).Problem
Verified Dependabot mechanics: SHA-pinned actions never produce Dependabot security alerts ("Dependabot ... will not create alerts for actions pinned to SHA values"), and security updates are triggered by alerts — so for a SHA-pinning org, every security-relevant action bump arrives as an ordinary version update, subject to cooldown (a 3-day default applies since 2026-07-14 even with no cooldown block), grouping, and the open-PR budget. anthropics/claude-code-action gets a cooldown exemption in this effort; the rest of the fleet's pinned dependencies have not been audited for equivalent staleness/exposure.
Related real-world precedent: CVE-2026-47751 was delivered to floating-tag users automatically; SHA-pinned users needed their own bump.
Task
Fleet-wide audit (subagent team run is fine) across all melodic-software repos:
uses:(actions + reusable workflows) and every in-workflow tool-version constant invisible to Dependabot (thetool-version-drift-check.ymlclass).