From 3d458041421d956968ba2d5941f5270fd9ab4ff2 Mon Sep 17 00:00:00 2001 From: Kyle Sexton <153232337+kyle-sexton@users.noreply.github.com> Date: Sun, 26 Jul 2026 11:12:15 -0400 Subject: [PATCH] chore(ci): bump the review reusables to pick up infra-failure classes MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This repository is where both silent-review blackouts were measured, and it is the one repository still blind to them: it pinned the review reusable at 90f1c54 (2026-07-18) and the security-review reusable at 99cb082 (2026-07-21), both of which predate the infra-failure classifier. When the lane fails here it reports green and says nothing about why. Bumps both to ci-workflows e295107, which carries the classifier from ci-workflows#248 plus the status/substring mirror fix from #249. Infra failures now emit a bare `class=` term in the job's ::error annotation and a `Failure class:` line in the marker-managed infra-status PR comment, with the numeric api_error_status in the safe projection. The classifier is already proven against a live production failure — the lane infra-failed on ci-workflows#248's own run and correctly emitted class=rate-limit with api_error_status 429. Interface compatibility checked rather than assumed: the workflow_call block of claude-review.yml is byte-identical across 90f1c54..e295107, and claude-security-review.yml differs only in the prose of an input default (the security prompt now defers to zizmor's static lane for supply-chain, trigger, permission, and template-injection findings). No input or secret was added, removed, or renamed. Co-authored-by: Claude Opus 5 (1M context) --- .github/workflows/claude-review.yml | 2 +- .github/workflows/claude-security-review.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml index fa7d08cd3d..fd1270aa69 100644 --- a/.github/workflows/claude-review.yml +++ b/.github/workflows/claude-review.yml @@ -22,7 +22,7 @@ jobs: contents: read # checkout + read the diff pull-requests: write # post review + track_progress tracking comment id-token: write # OIDC — mints the Claude GitHub App token - uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@90f1c54935203fa31b5b3d1f41531228be2c2b7f # 90f1c54 2026-07-18 + uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@e2951077a7b43c09fc5a8dee4da52ba6f0fb39ed # e295107 2026-07-26 infra-failure class in the annotation + PR comment with: runner: ubuntu-24.04 # Passing skip-actors replaces the reusable's default (dependabot[bot]), diff --git a/.github/workflows/claude-security-review.yml b/.github/workflows/claude-security-review.yml index 5266b4178c..517b245ac7 100644 --- a/.github/workflows/claude-security-review.yml +++ b/.github/workflows/claude-security-review.yml @@ -29,7 +29,7 @@ jobs: contents: read # checkout + read the diff pull-requests: write # post the security review id-token: write # OIDC — mints the Claude GitHub App token - uses: melodic-software/ci-workflows/.github/workflows/claude-security-review.yml@99cb082ebb942b9da08e8345a851be5bf252ad79 # 99cb082 2026-07-21 + uses: melodic-software/ci-workflows/.github/workflows/claude-security-review.yml@e2951077a7b43c09fc5a8dee4da52ba6f0fb39ed # e295107 2026-07-26 infra-failure class in the annotation + PR comment with: runner: ubuntu-24.04 skip-actors: "dependabot[bot],melodic-standards-sync[bot]"