Repository navigation
Compliance: non-stub-pr-review-mention.yml #330
Description
Activity
- addedcompliance-auditAutomated compliance audit findingAutomated compliance audit finding
on May 26, 2026 Dev-Lead Implementation Plan
Issue: #330 — Compliance: non-stub-pr-review-mention.yml
Scope
Replace the SHA-pinned
uses:reference in.github/workflows/pr-review-mention.ymlwith the org-standard semantic tag@v2.Implementation Checklist
-
.github/workflows/pr-review-mention.yml— changeuses:line from...@376a4fcb1117444595e3e702fa450873d0e54310 # v2to...@v2
Tests to Write
- N/A — pure CI configuration change with no observable behavioral change in the local test suite (TDD exception per AGENTS.md for behavior-preserving config fixes)
Test Command
npm test-
Dev-Lead: Implementation Complete
Plan Execution
-
.github/workflows/pr-review-mention.yml— replaced SHA-pinneduses:reference with@v2semantic tag
TDD Exception
Pure CI configuration change (no logic, no observable behavior change in the local test suite). No new tests written per the TDD exception clause.
Test Results
Test Suites: 12 passed, 12 total Tests: 301 passed, 301 total Snapshots: 0 total Time: 4.181 s Ran all test suites.Files Changed
.github/workflows/pr-review-mention.yml: changeduses:from...@376a4fcb1117444595e3e702fa450873d0e54310 # v2to...@v2, matching the canonical stub atpetry-projects/.github/standards/workflows/pr-review-mention.yml
Notes
- Pre-existing prettier warning in
.github/workflows/ci-failure-analyst.ymlis unrelated to this issue and was present before this change.
-
Weekly Compliance Audit (2026-05-29)
This finding is still open.
Detail: Centralized workflow
pr-review-mention.ymlreferences the reusable but is not pinned to@v2(org standard). Replace with the canonical stub fromstandards/workflows/pr-review-mention.ymlwhich delegates topetry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.- Already working on this: an open PR exists for issue #330.
Weekly Compliance Audit (2026-05-30)
This finding is still open.
Detail: Centralized workflow
pr-review-mention.ymlreferences the reusable but is not pinned to@v2(org standard). Replace with the canonical stub fromstandards/workflows/pr-review-mention.ymlwhich delegates topetry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.@don-petry-dev-lead
- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickupand removeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 3, 2026 Dev-Lead Implementation Plan
Issue: #330 — Compliance: non-stub-pr-review-mention.yml
Scope
Replace the SHA-pinned
uses:reference in.github/workflows/pr-review-mention.ymlwith the canonical@v2tag, matching the org-standard stub exactly.Implementation Checklist
- Update
.github/workflows/pr-review-mention.yml— changeuses:from...pr-review-mention-reusable.yml@<SHA> # v2to...pr-review-mention-reusable.yml@v2
Tests to Write
- N/A — this is a pure CI configuration change with no observable behavioral change (Phase 2 exception applies)
Test Command
npm testNotes
Per the org Action Pinning Policy, all actions must use SHA pins except internal reusable workflows, which use the version tag directly (e.g.
@v2). The current file incorrectly uses a SHA pin; the canonical stub atstandards/workflows/pr-review-mention.ymluses@v2.- Update
Weekly Compliance Audit (2026-06-05)
This finding is still open.
Detail: Centralized workflow
pr-review-mention.ymlreferences the reusable but is not pinned to@v2(org standard). Replace with the canonical stub fromstandards/workflows/pr-review-mention.ymlwhich delegates topetry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickupand removeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 6, 2026 Weekly Compliance Audit (2026-06-12)
This finding is still open.
Detail: Centralized workflow
pr-review-mention.ymlreferences the reusable but is not pinned to@v2(org standard). Replace with the canonical stub fromstandards/workflows/pr-review-mention.ymlwhich delegates topetry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickupand removeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 12, 2026 Weekly Compliance Audit (2026-06-19)
This finding is still open.
Detail: Centralized workflow
pr-review-mention.ymlreferences the reusable but is not pinned to@v2(org standard). Replace with the canonical stub fromstandards/workflows/pr-review-mention.ymlwhich delegates topetry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickupand removeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 19, 2026 Dev-Lead Implementation Plan
Issue: #330 — Compliance: non-stub-pr-review-mention.yml
Scope
Replace
.github/workflows/pr-review-mention.ymlwith the canonical org-standard thin-caller stub that delegates topetry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2(moving tag) instead of the current SHA-pinned ref.Implementation Checklist
- Overwrite
.github/workflows/pr-review-mention.ymlwith the canonical stub frompetry-projects/.github/standards/workflows/pr-review-mention.yml, preserving the@v2ref and the SOURCE-OF-TRUTH header comments
Tests to Write
- N/A — there is no test harness for
.github/workflows/*.ymlin this repo, and this is a behavior-preserving CI config change. Per the Phase 2 exception, TDD is skipped; verification is via lint + the existing test suite.
Test Command
npm test(full suite) andbash .dev-lead/scripts/dev-lead-lint.sh- Overwrite
Dev-Lead: Implementation Complete
Plan Execution
- Overwrote
.github/workflows/pr-review-mention.ymlwith the canonical org-standard thin-caller stub frompetry-projects/.github/standards/workflows/pr-review-mention.yml -
uses:ref changed from SHA-pin@376a4fcb…# v2→ moving tag@v2 - Added the SOURCE-OF-TRUTH header comments; preserved trigger events,
permissions:blocks, andsecrets: inherit
Test Results
$ bash .dev-lead/scripts/dev-lead-lint.sh [lint] shellcheck on 4 file(s)... [lint] all checks passed $ npx prettier --check .github/workflows/pr-review-mention.yml All matched files use Prettier code style! $ npm run check ✖ 22 problems (0 errors, 22 warnings) # warnings all pre-existing & unrelated (gmail-to-drive test files) $ npm test Test Suites: 12 passed, 12 total Tests: 301 passed, 301 total Snapshots: 0 total Time: 4.331 sFiles Changed
.github/workflows/pr-review-mention.yml: replaced SHA-pinned reusable ref with the canonical@v2thin-caller stub, matching the org standard byte-for-byte.
Notes
- TDD exception (Phase 2): This is a behavior-preserving CI workflow config change. The repo has no test harness for
.github/workflows/*.yml, so no test was added; verification was done via lint + the full existing suite. Per the Phase 2 exception for config/refactor changes with no observable behavioral change. npm run checklint warnings (22) are pre-existingno-unused-varswarnings in unrelatedgmail-to-drive-by-labelstest files — 0 errors, not introduced by this change.- No other caller workflows in this repo reference the SHA-pinned ref.
- Overwrote
Resolved! This check is now passing as of 2026-06-26. Closing automatically.
Compliance Finding
Category:
ci-workflowsSeverity:
errorCheck:
non-stub-pr-review-mention.ymlDetail
Centralized workflow
pr-review-mention.ymlreferences the reusable but is not pinned to@v2(org standard). Replace with the canonical stub fromstandards/workflows/pr-review-mention.ymlwhich delegates topetry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@v2.Standard Reference
standards/ci-standards.md#centralization-tiers
Remediation
Please review the linked standard and bring this repository into compliance.
See the full standards documentation for implementation guidance.
This issue was automatically created by the weekly compliance audit.