Skip to content

Compliance: non-stub-pr-review-mention.yml #330

Description

@don-petry

Compliance Finding

Category: ci-workflows
Severity: error
Check: non-stub-pr-review-mention.yml

Detail

Centralized workflow pr-review-mention.yml references the reusable but is not pinned to @v2 (org standard). Replace with the canonical stub from standards/workflows/pr-review-mention.yml which delegates to petry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.

Standard Reference

standards/ci-standards.md#centralization-tiers

Remediation

Please review the linked standard and bring this repository into compliance.

See the full standards documentation for implementation guidance.


This issue was automatically created by the weekly compliance audit.

Activity

  1. don-petry commented on May 26, 2026

    @don-petry
    CollaboratorAuthor

    Dev-Lead Implementation Plan

    Issue: #330 — Compliance: non-stub-pr-review-mention.yml

    Scope

    Replace the SHA-pinned uses: reference in .github/workflows/pr-review-mention.yml with the org-standard semantic tag @v2.

    Implementation Checklist

    • .github/workflows/pr-review-mention.yml — change uses: line from ...@376a4fcb1117444595e3e702fa450873d0e54310 # v2 to ...@v2

    Tests to Write

    • N/A — pure CI configuration change with no observable behavioral change in the local test suite (TDD exception per AGENTS.md for behavior-preserving config fixes)

    Test Command

    npm test

  2. don-petry commented on May 26, 2026

    @don-petry
    CollaboratorAuthor

    Dev-Lead: Implementation Complete

    Plan Execution

    • .github/workflows/pr-review-mention.yml — replaced SHA-pinned uses: reference with @v2 semantic tag

    TDD Exception

    Pure CI configuration change (no logic, no observable behavior change in the local test suite). No new tests written per the TDD exception clause.

    Test Results

    Test Suites: 12 passed, 12 total
    Tests:       301 passed, 301 total
    Snapshots:   0 total
    Time:        4.181 s
    Ran all test suites.
    

    Files Changed

    • .github/workflows/pr-review-mention.yml: changed uses: from ...@376a4fcb1117444595e3e702fa450873d0e54310 # v2 to ...@v2, matching the canonical stub at petry-projects/.github/standards/workflows/pr-review-mention.yml

    Notes

    • Pre-existing prettier warning in .github/workflows/ci-failure-analyst.yml is unrelated to this issue and was present before this change.
  3. don-petry commented on May 29, 2026

    @don-petry
    CollaboratorAuthor

    Weekly Compliance Audit (2026-05-29)

    This finding is still open.

    Detail: Centralized workflow pr-review-mention.yml references the reusable but is not pinned to @v2 (org standard). Replace with the canonical stub from standards/workflows/pr-review-mention.yml which delegates to petry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.

    Standard: standards/ci-standards.md#centralization-tiers

  4. don-petry commented on May 30, 2026

    @don-petry
    CollaboratorAuthor
    Already working on this: an open PR exists for issue #330.
  5. don-petry commented on May 30, 2026

    @don-petry
    CollaboratorAuthor

    Weekly Compliance Audit (2026-05-30)

    This finding is still open.

    Detail: Centralized workflow pr-review-mention.yml references the reusable but is not pinned to @v2 (org standard). Replace with the canonical stub from standards/workflows/pr-review-mention.yml which delegates to petry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.

    Standard: standards/ci-standards.md#centralization-tiers

  6. don-petry commented on May 30, 2026

    @don-petry
    CollaboratorAuthor
  7. don-petry commented on May 30, 2026

    @don-petry
    CollaboratorAuthor

    @don-petry-dev-lead

  8. added
    dev-leadFor dev-lead agent pickup
    and removed
    dev-leadFor dev-lead agent pickup
    on Jun 3, 2026
  9. don-petry commented on Jun 3, 2026

    @don-petry
    CollaboratorAuthor

    Dev-Lead Implementation Plan

    Issue: #330 — Compliance: non-stub-pr-review-mention.yml

    Scope

    Replace the SHA-pinned uses: reference in .github/workflows/pr-review-mention.yml with the canonical @v2 tag, matching the org-standard stub exactly.

    Implementation Checklist

    • Update .github/workflows/pr-review-mention.yml — change uses: from ...pr-review-mention-reusable.yml@<SHA> # v2 to ...pr-review-mention-reusable.yml@v2

    Tests to Write

    • N/A — this is a pure CI configuration change with no observable behavioral change (Phase 2 exception applies)

    Test Command

    npm test

    Notes

    Per the org Action Pinning Policy, all actions must use SHA pins except internal reusable workflows, which use the version tag directly (e.g. @v2). The current file incorrectly uses a SHA pin; the canonical stub at standards/workflows/pr-review-mention.yml uses @v2.

  10. don-petry commented on Jun 5, 2026

    @don-petry
    CollaboratorAuthor

    Weekly Compliance Audit (2026-06-05)

    This finding is still open.

    Detail: Centralized workflow pr-review-mention.yml references the reusable but is not pinned to @v2 (org standard). Replace with the canonical stub from standards/workflows/pr-review-mention.yml which delegates to petry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.

    Standard: standards/ci-standards.md#centralization-tiers

  11. added
    dev-leadFor dev-lead agent pickup
    and removed
    dev-leadFor dev-lead agent pickup
    on Jun 6, 2026
  12. don-petry commented on Jun 12, 2026

    @don-petry
    CollaboratorAuthor

    Weekly Compliance Audit (2026-06-12)

    This finding is still open.

    Detail: Centralized workflow pr-review-mention.yml references the reusable but is not pinned to @v2 (org standard). Replace with the canonical stub from standards/workflows/pr-review-mention.yml which delegates to petry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.

    Standard: standards/ci-standards.md#centralization-tiers

  13. added
    dev-leadFor dev-lead agent pickup
    and removed
    dev-leadFor dev-lead agent pickup
    on Jun 12, 2026
  14. don-petry commented on Jun 19, 2026

    @don-petry
    CollaboratorAuthor

    Weekly Compliance Audit (2026-06-19)

    This finding is still open.

    Detail: Centralized workflow pr-review-mention.yml references the reusable but is not pinned to @v2 (org standard). Replace with the canonical stub from standards/workflows/pr-review-mention.yml which delegates to petry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.

    Standard: standards/ci-standards.md#centralization-tiers

  15. added
    dev-leadFor dev-lead agent pickup
    and removed
    dev-leadFor dev-lead agent pickup
    on Jun 19, 2026
  16. don-petry commented on Jun 19, 2026

    @don-petry
    CollaboratorAuthor

    Dev-Lead Implementation Plan

    Issue: #330 — Compliance: non-stub-pr-review-mention.yml

    Scope

    Replace .github/workflows/pr-review-mention.yml with the canonical org-standard thin-caller stub that delegates to petry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2 (moving tag) instead of the current SHA-pinned ref.

    Implementation Checklist

    • Overwrite .github/workflows/pr-review-mention.yml with the canonical stub from petry-projects/.github/standards/workflows/pr-review-mention.yml, preserving the @v2 ref and the SOURCE-OF-TRUTH header comments

    Tests to Write

    • N/A — there is no test harness for .github/workflows/*.yml in this repo, and this is a behavior-preserving CI config change. Per the Phase 2 exception, TDD is skipped; verification is via lint + the existing test suite.

    Test Command

    npm test (full suite) and bash .dev-lead/scripts/dev-lead-lint.sh

  17. don-petry commented on Jun 19, 2026

    @don-petry
    CollaboratorAuthor

    Dev-Lead: Implementation Complete

    Plan Execution

    • Overwrote .github/workflows/pr-review-mention.yml with the canonical org-standard thin-caller stub from petry-projects/.github/standards/workflows/pr-review-mention.yml
    • uses: ref changed from SHA-pin @376a4fcb…# v2 → moving tag @v2
    • Added the SOURCE-OF-TRUTH header comments; preserved trigger events, permissions: blocks, and secrets: inherit

    Test Results

    $ bash .dev-lead/scripts/dev-lead-lint.sh
      [lint] shellcheck on 4 file(s)...
      [lint] all checks passed
    
    $ npx prettier --check .github/workflows/pr-review-mention.yml
    All matched files use Prettier code style!
    
    $ npm run check
    ✖ 22 problems (0 errors, 22 warnings)   # warnings all pre-existing & unrelated (gmail-to-drive test files)
    
    $ npm test
    Test Suites: 12 passed, 12 total
    Tests:       301 passed, 301 total
    Snapshots:   0 total
    Time:        4.331 s
    

    Files Changed

    • .github/workflows/pr-review-mention.yml: replaced SHA-pinned reusable ref with the canonical @v2 thin-caller stub, matching the org standard byte-for-byte.

    Notes

    • TDD exception (Phase 2): This is a behavior-preserving CI workflow config change. The repo has no test harness for .github/workflows/*.yml, so no test was added; verification was done via lint + the full existing suite. Per the Phase 2 exception for config/refactor changes with no observable behavioral change.
    • npm run check lint warnings (22) are pre-existing no-unused-vars warnings in unrelated gmail-to-drive-by-labels test files — 0 errors, not introduced by this change.
    • No other caller workflows in this repo reference the SHA-pinned ref.
  18. don-petry commented on Jun 26, 2026

    @don-petry
    CollaboratorAuthor

    Resolved! This check is now passing as of 2026-06-26. Closing automatically.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    compliance-auditAutomated compliance audit findingdev-leadFor dev-lead agent pickup

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions