Skip to content

chore: bump suite callers to reusable-security-suite@v1.25.0#84

Merged
dkastl merged 2 commits into
mainfrom
chore/suite-bump-v1.25.0
Jul 1, 2026
Merged

chore: bump suite callers to reusable-security-suite@v1.25.0#84
dkastl merged 2 commits into
mainfrom
chore/suite-bump-v1.25.0

Conversation

@dkastl

@dkastl dkastl commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Points the thin callers (security-suite.yml + picker template) at reusable-security-suite@v1.25.0, activating the robust in-job zizmor severity split (#83) through the ruleset. Also drops the now-unneeded checks: read from the caller suite jobs. Part of geolonia-operations#196.

Summary by CodeRabbit

  • Chores
    • Updated the security workflow to a newer pinned version.
    • No changes to app behavior, triggers, or user-facing features.

Activates the robust in-job severity split (#83) via the ruleset, and
drops the now-unneeded checks:read from the caller suite jobs (the report
job no longer reads the Checks API).
@github-actions

github-actions Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

🛡️ Security suite

Check Result
✅ Supply chain · bumblebee No exposure matches
✅ Secrets · betterleaks No secrets in diff
✅ Action pinning · pinact All actions pinned
❗ Actions audit · zizmor 6 error(s), 8 warning(s) (warn-only; see annotations)

Caution

zizmor found error-severity issues. They are warn-only (they do not block this PR), but please address them.

Updated for 0c07451 · workflow run

@coderabbitai

coderabbitai Bot commented Jul 1, 2026

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: ec4a2635-e3d1-4d24-9a15-bb4f5babbde5

📥 Commits

Reviewing files that changed from the base of the PR and between d3e2831 and 0c07451.

📒 Files selected for processing (2)
  • .github/workflows/security-suite.yml
  • workflow-templates/security-suite.yml

Walkthrough

Updates the pinned commit reference for the reusable security suite workflow from v1.24.0 to v1.25.0 in both the caller workflow and the workflow template, with no other structural changes.

Changes

Workflow Version Bump

Layer / File(s) Summary
Bump reusable workflow reference
.github/workflows/security-suite.yml, workflow-templates/security-suite.yml
The suite job's uses: pin for reusable-security-suite.yml is updated from the v1.24.0 commit SHA to the v1.25.0 commit SHA in both files.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

  • geolonia/.github#77: Also bumps the pinned commit/version used by the reusable security suite workflow.
  • geolonia/.github#79: Modifies the same .github/workflows/security-suite.yml reusable-workflow version pin at the same call site.
  • geolonia/.github#81: The bumped v1.25.0 ref pulls in changes from this related PR to the suite job.

Suggested labels: dependencies, github_actions

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/suite-bump-v1.25.0

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant