Skip to content

ci: review-pin actions/setup-go v7.0.0 and setup-node v7.0.0 - #41

Merged
sumitake merged 2 commits into
mainfrom
dev/grok/setup-go-node-v7
Aug 28, 2026
Merged

ci: review-pin actions/setup-go v7.0.0 and setup-node v7.0.0#41
sumitake merged 2 commits into
mainfrom
dev/grok/setup-go-node-v7

Conversation

@sumitake

Copy link
Copy Markdown
Owner

Supersedes Dependabot PRs #9 (setup-go 6.5.0 → 7.0.0) and #5 (setup-node 6.4.0 → 7.0.0).

Those PRs selected the tagged SHAs but could not pass scripts/check_workflow_policy.py because REVIEWED_ACTION_PINS still named the v6 pins. This change updates the workflows and the reviewed pin table together.

Verified:

  • actions/setup-go@v7.0.0 == b7ad1dad31e06c5925ef5d2fc7ad053ef454303e
  • actions/setup-node@v7.0.0 == 820762786026740c76f36085b0efc47a31fe5020
  • python3 scripts/check_workflow_policy.py .github/workflows passed
  • python3 -m unittest tests.repository.test_workflow_policy -v passed (41 tests)

Dependabot PRs #9 and #5 already selected the tagged SHAs. Update the
reviewed pin table in the same change so workflow policy stays closed.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 99b1a08f-f22c-4b12-bfbb-96243edf212a


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sumitake
sumitake merged commit 12f6cd3 into main Aug 28, 2026
18 checks passed
@sumitake
sumitake deleted the dev/grok/setup-go-node-v7 branch August 28, 2026 07:21
cursor Bot pushed a commit that referenced this pull request Aug 28, 2026
The push/schedule sanitizer (--tracked --history) already failed these
six deterministic findings on d880c0f and still fails them on the PR #41
pin bump. Tracked scan is clean; this does not change the scanner, skip
--history, or broaden beyond the six denies.

Add history-blob allowlist entries for
cmd/portable-ghar-runtime-lock/main_test.go@99d55b0de82a227bcfd52f4b9ca64130db9c4338
lines 43 (DEPLOYID002), 53 (URI001), and 74 (DEPLOYID002), matching the
existing @504a9c865eb35654def0a297c05c2b3b25b80895 exceptions. The flagged
lines are byte-identical; hashes were computed with the scanner's own
line hasher against the full blob OID.

Add the Cursor Agent cursor.com identity and the unprefixed
users.noreply.github.com co-author form to PUBLIC_HISTORY_METADATA_LINES.
Keep the existing GitHub-id form.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
sumitake added a commit that referenced this pull request Aug 28, 2026
The push/schedule sanitizer (--tracked --history) already failed these
six deterministic findings on d880c0f and still fails them on the PR #41
pin bump. Tracked scan is clean; this does not change the scanner, skip
--history, or broaden beyond the six denies.

Add history-blob allowlist entries for
cmd/portable-ghar-runtime-lock/main_test.go@99d55b0de82a227bcfd52f4b9ca64130db9c4338
lines 43 (DEPLOYID002), 53 (URI001), and 74 (DEPLOYID002), matching the
existing @504a9c865eb35654def0a297c05c2b3b25b80895 exceptions. The flagged
lines are byte-identical; hashes were computed with the scanner's own
line hasher against the full blob OID.

Add the Cursor Agent cursor.com identity and the unprefixed
users.noreply.github.com co-author form to PUBLIC_HISTORY_METADATA_LINES.
Keep the existing GitHub-id form.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant