Skip to content

chore(claude-lanes): re-pin the review lanes to ci-workflows v0.11.0 - #2079

Merged
kyle-sexton merged 2 commits into
mainfrom
chore/repin-claude-lanes-v0.11.0
Aug 9, 2026
Merged

kyle-sexton merged 2 commits into
mainfrom
chore/repin-claude-lanes-v0.11.0

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

No linked issue

Summary

Re-pin the two locally-owned lane callers to ci-workflows v0.11.0 (ee96bd28a43eebfa06b61aee8b518cc5b1b195b3). Contract-diff between v0.10.2 and v0.11.0: the lanes add or remove no input, secret, output, or caller permission, so the pin lines are the entire change. The lane deltas are internal — fail-closed on a claude-code-action workflow-validation self-skip, a drop-proof inline-comment grant in the security lane (ci-workflows#382, ci-workflows#395), and a claude-code-action bump to 1.0.187.

.github/standards/runner-policy/policy.json here is a MANAGED materialization and is deliberately untouched — it arrives via the standards sync.

Dependency ordering

DO NOT MERGE until the standards sync delivers the updated runner-policy materialization. Until then the runner-policy gate on this branch is EXPECTED RED: the pinned ee96bd2 revision is not yet in the local policy.json allowlist. Sequence: melodic-software/standards repin PR merges, sync.yml opens the sync PR here, sync PR merges, re-run CI on this branch, gate goes green, drop the do-not-merge label, merge.

Verification

  • Pin format matches the pin-comment convention (@<sha> # v0.11.0)
  • Signed commit; two-line diff
  • Runner-policy gate: expected red pre-sync, green post-sync (see ordering above)

Related

  • ci-workflows#382

🤖 Generated with Claude Code

https://claude.ai/code/session_011eQuk4u41GgXpv1zJwwkkH

Same major version as the pins they replace (v0.10.2). The v0.11.0 lane
contracts add or remove no input, secret, or caller permission; the
lane deltas are internal (fail-closed on a workflow-validation
self-skip, drop-proof inline-comment grant in the security lane, and a
claude-code-action bump to 1.0.187). The runner-policy materialization
here is managed and arrives by standards sync; this bump touches only
the two locally-owned callers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HCJfVqDNYt92YRyvKUMgYW
@kyle-sexton kyle-sexton added the do-not-merge Hard merge gate: do not merge while applied. label Aug 9, 2026
@cursor

cursor Bot commented Aug 9, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

kyle-sexton added a commit to melodic-software/standards that referenced this pull request Aug 9, 2026
…343)

No linked issue

## Summary

Fleet repin of the Claude review lanes from ci-workflows v0.10.2 to
v0.11.0 (`ee96bd28a43eebfa06b61aee8b518cc5b1b195b3`), following the
v0.10.2 precedent shape:

- `components/claude-lanes/`: all four pins rewritten via
`repin-callers.sh apply v0.11.0 <sha>` (selector + lane reusable in each
caller component).
- `.github/workflows/claude-review.yml`: the repo-local caller's single
pin, hand-edited (manifest source, not a sync target).
- `components/runner-policy/policy.json`: the v0.11.0 selector revision
appended to the owner-scoped allowlist (the selector is byte-identical
to `e9443874`, but the allowlist keys on the pinned SHA the components
now carry), and two `approvedReusableWorkflowContracts` entries added
under the new SHA keys — verbatim copies of their `e9443874`
predecessors, because the contract-diff between the tags shows no input,
secret, output, or caller-permission change in either lane.
- `components/runner-policy/runner-policy.test.mjs`: new
`DROP_PROOF_GRANT_LANE_SHA` constant appended to the selector-allowlist
expectation.
- `components/runner-policy/README.md`: revision-history prose for the
v0.11.0 revision (contract-diff verdict, the security lane's
`claude-args` default moving its inline-comment grant into a drop-proof
compose step per ci-workflows#382 / ci-workflows#395, the fail-closed
validation-skip behavior, the action bump) and both revision counts
bumped.

## Verification

- `node --test components/runner-policy/runner-policy.test.mjs`
(242/242)
- `npm run lint:runner-policy` ("Runner policy passed.")
- `components/claude-lanes/claude-lanes.test.sh` checks 1-8 (component
materialization + actionlint + findings) pass locally; the sync-target
materialization phase (checks 9+) and `go-analysis` /
`markdownlint-home` fail or stall locally on pre-existing Windows
tmp-path and toolchain-cache environment issues also present on an
unmodified base — Linux CI is authoritative for those.
- `components/claude-lanes/repin-callers.test.sh` passes.
- Pre-commit hooks (markdownlint, biome, typos, gitleaks, editorconfig)
green on the commit.

## Rollout ordering

After this merges, `sync.yml` delivers the updated runner-policy
materialization to consumers; melodic-software/claude-code-plugins#2079
(labeled do-not-merge) stays red on its runner-policy gate until that
sync lands there. melodic-software/claude-lane-sandbox#4 is hand-wired
and independent.

## Related

- ci-workflows#382

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_011eQuk4u41GgXpv1zJwwkkH

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
kyle-sexton added a commit to melodic-software/claude-lane-sandbox that referenced this pull request Aug 9, 2026
)

Re-pins the hand-wired lane caller from v0.10.2 (`e9443874`) to v0.11.0
(`ee96bd28a43eebfa06b61aee8b518cc5b1b195b3`). This fixture is locally
owned and deliberately not a sync-manifest target; the pin moves by
hand, mirroring the fleet repin (standards#344,
claude-code-plugins#2079).

This PR closes nothing.

## Related

No linked issue. For reference: melodic-software/standards#344,
melodic-software/claude-code-plugins#2079.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01HCJfVqDNYt92YRyvKUMgYW

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@kyle-sexton kyle-sexton removed the do-not-merge Hard merge gate: do not merge while applied. label Aug 9, 2026
@kyle-sexton
kyle-sexton merged commit 14a38f8 into main Aug 9, 2026
32 of 34 checks passed
@kyle-sexton
kyle-sexton deleted the chore/repin-claude-lanes-v0.11.0 branch August 9, 2026 15:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant