chore(ci): correct CodeQL pinned-version annotations - #46
Draft
PeterGuy326 wants to merge 2 commits into
Draft
PeterGuy326 wants to merge 2 commits into
PeterGuy326 wants to merge 2 commits into
Conversation
Annotate the existing cdf488f595d80d6e07e03d4674febd5ab45fa938 pin as v4.37.9. The action SHA and executable workflow configuration are unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Canonical requirement
Refs bytefolk/.github#32
Decision reference: the initial R1 Issue body. It explicitly records that local candidates preceded this prospective publication record; no retrospective approval is claimed.
Requirement trace
File domains
.github/workflows/bytefolk-scorecard.yml(47);.github/workflows/bytefolk-security.yml(56, 62).Base:
65068136a1e2914c59063905b19a6956105ba3cbHead:
ec31e73d50eb5999b2e31c943d6ceb34c6ee3591Scope and non-goals
Correct only
# v4.37.4to# v4.37.9on CodeQL uses-lines pinned tocdf488f595d80d6e07e03d4674febd5ab45fa938. The official tag object resolves to that existing pin. Action SHAs, permissions, triggers, steps, matrices, other pins, and runtime code are unchanged.Validation
ruby evidence/verify.rb --baselineandruby evidence/verify.rb --committedfrom the retained review packet;git diff --check 65068136a1e2914c59063905b19a6956105ba3cb ec31e73d50eb5999b2e31c943d6ceb34c6ee3591from this repository.The strict verifier checks the changed-file allowlist; exact old blobs and line inventory; complete expected-byte replacement; absence of stale target annotations; parsed YAML equality; comment-stripped byte equality and SHA-256 digests; whitespace and unchanged modes; one commit with the exact parent; and clean worktrees with no untracked files. All passed. The independent replay is recorded in canonical R1. The verifier and inventory are retained outside repository commits.
ruby evidence/verify.rb --committedSecurity and compatibility
Documentation annotation only. No dependencies, permissions, credentials, data flows, or runtime behavior change. The diff and commit identity were inspected for public-safe content. No CHANGELOG entry or behavior-documentation update is needed because only explanatory comments change.
Known limitations
Runtime suites, build, coverage, and dependency audits were not rerun for this comment-only change; no runtime test result is claimed. Hosted CI is separate from local equality proof. This is a draft, not merge-ready.
Risk and rollback
Low-risk annotation correction. Roll back through an ordinary revert of this single commit. There is no migration or release action.
Product review handoff