fix: bump required-workflow ref to v1.30.0 (whole tree now immutable) [2/2]#90
Conversation
… [2/2] Part 2 of 2. reusable-security-suite@v1.30.0 (76db4b3) has SHA-pinned scanner refs (#89), so pointing security-suite.yml's REF2 at it makes the ENTIRE required-workflow reusable tree immutable. This is the topology the ruleset 'require workflows' injector needs; identical shape to the last-known-working v1.25.0 but with the #85 severity breakdown + #87 hardening. After release v1.31.0 and @v1 advancing, re-trigger a consumer PR to confirm the Security Suite check runs again.
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
WalkthroughUpdates the pinned commit SHA reference for the reusable security suite workflow in security-suite.yml from v1.28.0 to v1.30.0, changing which version of the suite executes without altering workflow wiring, triggers, concurrency, or permissions. ChangesSecurity Suite Version Bump
Estimated code review effort: 1 (Trivial) | ~2 minutes Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
🛡️ Security suite
Note All security checks passed. Updated for |
|
@coderabbitai review |
✅ Action performedReview finished.
|
Part 2 of 2 — completes the fix for the org-wide Security Suite required check.
reusable-security-suite@v1.30.0(#89) SHA-pinned its scanner refs, so pointingsecurity-suite.yml's reusable ref at it makes the entire required-workflow reusable tree immutable:This is the same shape as the last-known-working v1.25.0 (fully SHA-pinned), now with the
#85severity breakdown +#87hardening. The ruleset "require workflows" injector needs exactly this (no moving tags anywhere in the tree).After merge
Cut v1.31.0 →
@v1advances → re-trigger a consumer PR (infra-cdk#151) → confirm the Security Suite check finally runs. That's the real verification; I'll hold the "fixed" call until then.Validation:
pinact --checkexit 0,zizmorclean, no em-dashes.Summary by CodeRabbit