chore(claude-lanes): re-pin the review lanes to ci-workflows v0.11.0 - #2079
Merged
Merged
Conversation
Same major version as the pins they replace (v0.10.2). The v0.11.0 lane contracts add or remove no input, secret, or caller permission; the lane deltas are internal (fail-closed on a workflow-validation self-skip, drop-proof inline-comment grant in the security lane, and a claude-code-action bump to 1.0.187). The runner-policy materialization here is managed and arrives by standards sync; this bump touches only the two locally-owned callers. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HCJfVqDNYt92YRyvKUMgYW
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
kyle-sexton
added a commit
to melodic-software/standards
that referenced
this pull request
Aug 9, 2026
…343) No linked issue ## Summary Fleet repin of the Claude review lanes from ci-workflows v0.10.2 to v0.11.0 (`ee96bd28a43eebfa06b61aee8b518cc5b1b195b3`), following the v0.10.2 precedent shape: - `components/claude-lanes/`: all four pins rewritten via `repin-callers.sh apply v0.11.0 <sha>` (selector + lane reusable in each caller component). - `.github/workflows/claude-review.yml`: the repo-local caller's single pin, hand-edited (manifest source, not a sync target). - `components/runner-policy/policy.json`: the v0.11.0 selector revision appended to the owner-scoped allowlist (the selector is byte-identical to `e9443874`, but the allowlist keys on the pinned SHA the components now carry), and two `approvedReusableWorkflowContracts` entries added under the new SHA keys — verbatim copies of their `e9443874` predecessors, because the contract-diff between the tags shows no input, secret, output, or caller-permission change in either lane. - `components/runner-policy/runner-policy.test.mjs`: new `DROP_PROOF_GRANT_LANE_SHA` constant appended to the selector-allowlist expectation. - `components/runner-policy/README.md`: revision-history prose for the v0.11.0 revision (contract-diff verdict, the security lane's `claude-args` default moving its inline-comment grant into a drop-proof compose step per ci-workflows#382 / ci-workflows#395, the fail-closed validation-skip behavior, the action bump) and both revision counts bumped. ## Verification - `node --test components/runner-policy/runner-policy.test.mjs` (242/242) - `npm run lint:runner-policy` ("Runner policy passed.") - `components/claude-lanes/claude-lanes.test.sh` checks 1-8 (component materialization + actionlint + findings) pass locally; the sync-target materialization phase (checks 9+) and `go-analysis` / `markdownlint-home` fail or stall locally on pre-existing Windows tmp-path and toolchain-cache environment issues also present on an unmodified base — Linux CI is authoritative for those. - `components/claude-lanes/repin-callers.test.sh` passes. - Pre-commit hooks (markdownlint, biome, typos, gitleaks, editorconfig) green on the commit. ## Rollout ordering After this merges, `sync.yml` delivers the updated runner-policy materialization to consumers; melodic-software/claude-code-plugins#2079 (labeled do-not-merge) stays red on its runner-policy gate until that sync lands there. melodic-software/claude-lane-sandbox#4 is hand-wired and independent. ## Related - ci-workflows#382 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_011eQuk4u41GgXpv1zJwwkkH Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
kyle-sexton
added a commit
to melodic-software/claude-lane-sandbox
that referenced
this pull request
Aug 9, 2026
) Re-pins the hand-wired lane caller from v0.10.2 (`e9443874`) to v0.11.0 (`ee96bd28a43eebfa06b61aee8b518cc5b1b195b3`). This fixture is locally owned and deliberately not a sync-manifest target; the pin moves by hand, mirroring the fleet repin (standards#344, claude-code-plugins#2079). This PR closes nothing. ## Related No linked issue. For reference: melodic-software/standards#344, melodic-software/claude-code-plugins#2079. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01HCJfVqDNYt92YRyvKUMgYW Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No linked issue
Summary
Re-pin the two locally-owned lane callers to ci-workflows v0.11.0 (
ee96bd28a43eebfa06b61aee8b518cc5b1b195b3). Contract-diff between v0.10.2 and v0.11.0: the lanes add or remove no input, secret, output, or caller permission, so the pin lines are the entire change. The lane deltas are internal — fail-closed on a claude-code-action workflow-validation self-skip, a drop-proof inline-comment grant in the security lane (ci-workflows#382, ci-workflows#395), and a claude-code-action bump to 1.0.187..github/standards/runner-policy/policy.jsonhere is a MANAGED materialization and is deliberately untouched — it arrives via the standards sync.Dependency ordering
DO NOT MERGE until the standards sync delivers the updated runner-policy materialization. Until then the runner-policy gate on this branch is EXPECTED RED: the pinned
ee96bd2revision is not yet in the localpolicy.jsonallowlist. Sequence: melodic-software/standards repin PR merges,sync.ymlopens the sync PR here, sync PR merges, re-run CI on this branch, gate goes green, drop thedo-not-mergelabel, merge.Verification
@<sha> # v0.11.0)Related
🤖 Generated with Claude Code
https://claude.ai/code/session_011eQuk4u41GgXpv1zJwwkkH