Skip to content

fix(ci): maintain workflow dependencies through canonical provenance - #91

Merged
rldyourmnd merged 3 commits into
mainfrom
fix/canonical-workflow-dependencies-20260907
Sep 7, 2026
Merged

fix(ci): maintain workflow dependencies through canonical provenance#91
rldyourmnd merged 3 commits into
mainfrom
fix/canonical-workflow-dependencies-20260907

Conversation

@rldyourmnd

@rldyourmnd rldyourmnd commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Dependabot #84 edited the generated Go caller directly, which left its anchor and bundle provenance at the previous reusable reference. Natural CI failures #85, #86 and #87 reported that mismatch.

This replacement adopts the proposed immutable references through ci.workflow_ref, regenerates the caller and bundle lock with GDS, and corrects the publisher commit annotation. The Go and CodeQL reusable workflow contents are identical between the old and new CI refs. The Dependabot ignore now names only the actual generated Go dependency; independent workflow proposals remain enabled. Obsolete instructions naming nonexistent scripts are removed.

Validation: 47 Python tests, actionlint and repeated native projection checks passed. Full Go quick validation passed after regenerating the projection goldens from the changed anchor; the context and projection regressions also passed. Original bot history is preserved; this replacement uses signed canonical author commits.

Closes #85.
Closes #86.
Closes #87.
Supersedes #84 after integration.

Signed-off-by: rldyourmnd <danil@nddev.it.com>
Signed-off-by: rldyourmnd <danil@nddev.it.com>
Signed-off-by: rldyourmnd <danil@nddev.it.com>
@rldyourmnd
rldyourmnd merged commit be30090 into main Sep 7, 2026
7 checks passed
@rldyourmnd
rldyourmnd deleted the fix/canonical-workflow-dependencies-20260907 branch September 7, 2026 07:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant