chore(claude-lanes): re-pin the review lanes to ci-workflows v0.11.0 - #343
Merged
Merged
Conversation
Same major version as the pins they replace (v0.10.2 to v0.11.0). The v0.11.0 lane contracts add or remove no input, secret, or caller permission and keep the runner-input routing surface, so the two new approvedReusableWorkflowContracts entries are verbatim copies of their e9443874 predecessors under the new SHA key. The selector is byte-identical to e9443874; its new revision is appended to the owner-scoped allowlist because the components now pin it at the v0.11.0 SHA. One declared default moved inside the security lane: claude-args drops the inline-comment grant, which now rides a compose step that appends it after the caller's args (ci-workflows#382, ci-workflows#395); effective grants are unchanged. The policy README's revision history records the internal deltas (fail-closed on a workflow-validation self-skip, review-count crediting, action bump to 1.0.187). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HCJfVqDNYt92YRyvKUMgYW
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No linked issue
Summary
Fleet repin of the Claude review lanes from ci-workflows v0.10.2 to v0.11.0 (
ee96bd28a43eebfa06b61aee8b518cc5b1b195b3), following the v0.10.2 precedent shape:components/claude-lanes/: all four pins rewritten viarepin-callers.sh apply v0.11.0 <sha>(selector + lane reusable in each caller component)..github/workflows/claude-review.yml: the repo-local caller's single pin, hand-edited (manifest source, not a sync target).components/runner-policy/policy.json: the v0.11.0 selector revision appended to the owner-scoped allowlist (the selector is byte-identical toe9443874, but the allowlist keys on the pinned SHA the components now carry), and twoapprovedReusableWorkflowContractsentries added under the new SHA keys — verbatim copies of theire9443874predecessors, because the contract-diff between the tags shows no input, secret, output, or caller-permission change in either lane.components/runner-policy/runner-policy.test.mjs: newDROP_PROOF_GRANT_LANE_SHAconstant appended to the selector-allowlist expectation.components/runner-policy/README.md: revision-history prose for the v0.11.0 revision (contract-diff verdict, the security lane'sclaude-argsdefault moving its inline-comment grant into a drop-proof compose step per ci-workflows#382 / ci-workflows#395, the fail-closed validation-skip behavior, the action bump) and both revision counts bumped.Verification
node --test components/runner-policy/runner-policy.test.mjs(242/242)npm run lint:runner-policy("Runner policy passed.")components/claude-lanes/claude-lanes.test.shchecks 1-8 (component materialization + actionlint + findings) pass locally; the sync-target materialization phase (checks 9+) andgo-analysis/markdownlint-homefail or stall locally on pre-existing Windows tmp-path and toolchain-cache environment issues also present on an unmodified base — Linux CI is authoritative for those.components/claude-lanes/repin-callers.test.shpasses.Rollout ordering
After this merges,
sync.ymldelivers the updated runner-policy materialization to consumers; melodic-software/claude-code-plugins#2079 (labeled do-not-merge) stays red on its runner-policy gate until that sync lands there. melodic-software/claude-lane-sandbox#4 is hand-wired and independent.Related
🤖 Generated with Claude Code
https://claude.ai/code/session_011eQuk4u41GgXpv1zJwwkkH