Skip to content

chore(claude-lanes): re-pin the review lanes to ci-workflows v0.11.0 - #343

Merged
kyle-sexton merged 1 commit into
mainfrom
chore/repin-claude-lanes-v0.11.0
Aug 9, 2026
Merged

kyle-sexton merged 1 commit into
mainfrom
chore/repin-claude-lanes-v0.11.0

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

No linked issue

Summary

Fleet repin of the Claude review lanes from ci-workflows v0.10.2 to v0.11.0 (ee96bd28a43eebfa06b61aee8b518cc5b1b195b3), following the v0.10.2 precedent shape:

  • components/claude-lanes/: all four pins rewritten via repin-callers.sh apply v0.11.0 <sha> (selector + lane reusable in each caller component).
  • .github/workflows/claude-review.yml: the repo-local caller's single pin, hand-edited (manifest source, not a sync target).
  • components/runner-policy/policy.json: the v0.11.0 selector revision appended to the owner-scoped allowlist (the selector is byte-identical to e9443874, but the allowlist keys on the pinned SHA the components now carry), and two approvedReusableWorkflowContracts entries added under the new SHA keys — verbatim copies of their e9443874 predecessors, because the contract-diff between the tags shows no input, secret, output, or caller-permission change in either lane.
  • components/runner-policy/runner-policy.test.mjs: new DROP_PROOF_GRANT_LANE_SHA constant appended to the selector-allowlist expectation.
  • components/runner-policy/README.md: revision-history prose for the v0.11.0 revision (contract-diff verdict, the security lane's claude-args default moving its inline-comment grant into a drop-proof compose step per ci-workflows#382 / ci-workflows#395, the fail-closed validation-skip behavior, the action bump) and both revision counts bumped.

Verification

  • node --test components/runner-policy/runner-policy.test.mjs (242/242)
  • npm run lint:runner-policy ("Runner policy passed.")
  • components/claude-lanes/claude-lanes.test.sh checks 1-8 (component materialization + actionlint + findings) pass locally; the sync-target materialization phase (checks 9+) and go-analysis / markdownlint-home fail or stall locally on pre-existing Windows tmp-path and toolchain-cache environment issues also present on an unmodified base — Linux CI is authoritative for those.
  • components/claude-lanes/repin-callers.test.sh passes.
  • Pre-commit hooks (markdownlint, biome, typos, gitleaks, editorconfig) green on the commit.

Rollout ordering

After this merges, sync.yml delivers the updated runner-policy materialization to consumers; melodic-software/claude-code-plugins#2079 (labeled do-not-merge) stays red on its runner-policy gate until that sync lands there. melodic-software/claude-lane-sandbox#4 is hand-wired and independent.

Related

  • ci-workflows#382

🤖 Generated with Claude Code

https://claude.ai/code/session_011eQuk4u41GgXpv1zJwwkkH

Same major version as the pins they replace (v0.10.2 to v0.11.0). The
v0.11.0 lane contracts add or remove no input, secret, or caller
permission and keep the runner-input routing surface, so the two new
approvedReusableWorkflowContracts entries are verbatim copies of their
e9443874 predecessors under the new SHA key. The selector is
byte-identical to e9443874; its new revision is appended to the
owner-scoped allowlist because the components now pin it at the
v0.11.0 SHA. One declared default moved inside the security lane:
claude-args drops the inline-comment grant, which now rides a compose
step that appends it after the caller's args (ci-workflows#382,
ci-workflows#395); effective grants are unchanged. The policy README's
revision history records the internal deltas (fail-closed on a
workflow-validation self-skip, review-count crediting, action bump to
1.0.187).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HCJfVqDNYt92YRyvKUMgYW
@cursor

cursor Bot commented Aug 9, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@kyle-sexton
kyle-sexton merged commit f6ebac6 into main Aug 9, 2026
43 checks passed
@kyle-sexton
kyle-sexton deleted the chore/repin-claude-lanes-v0.11.0 branch August 9, 2026 14:49
@kyle-sexton
kyle-sexton restored the chore/repin-claude-lanes-v0.11.0 branch August 9, 2026 15:00
@kyle-sexton
kyle-sexton deleted the chore/repin-claude-lanes-v0.11.0 branch August 9, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant