Skip to content

[Phase 2 follow-up] Complete the #1184 legacy→major-scoped pin migration in the reusable-pin compliance check (split from #687 ACs 7–13) #1493

Description

@don-petry

Story

As the maintainer of the pinning standard,
I want the reusable-pin compliance check (shipped for original-scope #687 by #1449) extended to complete the #1184 legacy → major-scoped channel migration,
so that the canonical pin form is <name>/v<MAJOR>-<tier>, every legacy pin is inventoried and repinned, and enforcement flips only once the migration is provably complete.

Split out of #687 (its ACs 7–13, which lived comment-only and were invisible to the sub-issue DAG). #687's original ACs 1–6 were delivered by #1449 (merged 2026-08-08) and it is closed. The AC numbering below is preserved from the #687 scope-extension comment (2026-08-03) for traceability; that comment holds the full evidence tables (7 legacy vs 10 major-scoped pins, Class A/Class B split).

Acceptance Criteria

  1. Canonical form corrected. The sanctioned form is the major-scoped channel <name>/v<MAJOR>-<tier> (tiers stable/next/ring0/ring1) or an immutable <name>/vX.Y.Z. The check must not present bare <name>/<tier> as canonical.
  2. Legacy is classified, not silently passed. A bare <name>/<tier> ref is reported as DEPRECATED with file, line, and the major-scoped ref it should become. During the migration window this is a warning, not a failure (so main stays green).
  3. Inventory is complete and machine-readable. The check emits every legacy pin across .github/workflows/** and templates/** with counts in the run summary. Expected starting point: 7 legacy / 10 major-scoped (per the [Phase 2] Generalized CI compliance test: reject SHA / # main pins on any first-party reusable #687 extension comment); deviation means the scan missed something.
  4. Class B prerequisite. pr-review/v1-stable and pr-review/v1-next are cut via scripts/cut-release.sh from the commits the current legacy channels point at (tag move, no content change), recorded in docs/release/versioning.md. Do not flip enforcement before this — pr-review has no major-scoped tags, and an early flip fails main and halts all review via the [Phase 4] pr-review defers indefinitely on another agent's own check run (dev-lead/dispatch) and on zombie checks — ci-pending has no timeout #1427 AC Workflow should skip no-op PRs in MAX_PRS count #7 mechanism.
  5. Repin sweep. All 7 legacy pins repinned to major-scoped equivalents; ring-0 frozen stubs regenerated via caller_stub_freeze.sh --update in the same reviewed diff, per AGENTS.md.
  6. Enforcement flip. DEPRECATED becomes a failure as a separate, explicitly-called-out change after ACs 10–11 are complete.
  7. No reintroduction via the generator. A test asserts a canonical stub pinned @<name>/v<MAJOR>-stable round-trips through seed-repo-template.sh unchanged. Supersedes [bug] seed-repo-template.sh repins caller stubs to pre-#1184 legacy channels — template-drift enforces a baseline that contradicts standards #1436 AC feat: add Copilot engine support via REVIEW_ENGINE toggle #5; the guard [bug] seed-repo-template fetches standards unpinned — pin to published stable, compliance accepts N-1 (continues #1436) #1448 should reference.

Tasks / Subtasks

  • Amend the classifier: major-scoped = sanctioned, bare tier = DEPRECATED + suggested replacement. (AC: 7, 8)
  • Emit inventory + counts in the run summary. (AC: 9)
  • Cut pr-review/v1-stable + pr-review/v1-next at the current legacy channel commits. (AC: 10)
  • Repin the 7 legacy refs; regenerate frozen baselines in the same diff. (AC: 11)
  • Flip DEPRECATED → failure as a discrete change. (AC: 12)
  • Add the generator round-trip test. (AC: 13)
  • Update AGENTS.md "Release channel tags" examples to major-scoped form, marking bare <name>/<tier> legacy.

Dev Notes

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dev-leadFor dev-lead agent pickupenhancementFeature requestsinitiativeEpic / initiative tracking issue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions