Skip to content

chore(ci): correct CodeQL pinned-version annotations - #46

Draft
PeterGuy326 wants to merge 2 commits into
mainfrom
codex/32-codeql-version-comments
Draft

PeterGuy326 wants to merge 2 commits into
mainfrom
codex/32-codeql-version-comments

Conversation

@PeterGuy326

Copy link
Copy Markdown
Contributor

Canonical requirement

Refs bytefolk/.github#32

Decision reference: the initial R1 Issue body. It explicitly records that local candidates preceded this prospective publication record; no retrospective approval is claimed.

Requirement trace

REQ/AC IDs Changed files / domain Tests or review evidence
REQ-001 / AC-001 3 exact-pinned version annotations Exact expected-byte replacement PASS
REQ-002 / AC-002 2 files in bytefolk/doc Repository inventory PASS; aggregate 7 repositories, 13 files, 21 lines
REQ-003 / AC-003 Existing workflow content and modes Parsed YAML and comment-stripped bytes identical
REQ-004 / AC-004 Current-head CI and independent review Local independent replay recorded in the canonical R1 Issue linked above; hosted CI and merge review remain pending

File domains

.github/workflows/bytefolk-scorecard.yml (47); .github/workflows/bytefolk-security.yml (56, 62).

Base: 65068136a1e2914c59063905b19a6956105ba3cb
Head: ec31e73d50eb5999b2e31c943d6ceb34c6ee3591

Scope and non-goals

Correct only # v4.37.4 to # v4.37.9 on CodeQL uses-lines pinned to cdf488f595d80d6e07e03d4674febd5ab45fa938. The official tag object resolves to that existing pin. Action SHAs, permissions, triggers, steps, matrices, other pins, and runtime code are unchanged.

Validation

  • Exact commands: ruby evidence/verify.rb --baseline and ruby evidence/verify.rb --committed from the retained review packet; git diff --check 65068136a1e2914c59063905b19a6956105ba3cb ec31e73d50eb5999b2e31c943d6ceb34c6ee3591 from this repository.
  • Observed counts/results: PASS 2/2 files and 3/3 replacements here; aggregate PASS 13/13 files and 21/21 replacements. Baseline intentionally exits 1 after detecting all 21 stale annotations; committed verification exits 0.
  • Check URLs: NOT VERIFIED: this draft is published before its hosted check results exist.

The strict verifier checks the changed-file allowlist; exact old blobs and line inventory; complete expected-byte replacement; absence of stale target annotations; parsed YAML equality; comment-stripped byte equality and SHA-256 digests; whitespace and unchanged modes; one commit with the exact parent; and clean worktrees with no untracked files. All passed. The independent replay is recorded in canonical R1. The verifier and inventory are retained outside repository commits.

ID REQ/AC Observable acceptance criterion Command or manual steps Environment Expected Observed Status
V1 AC-001, AC-002, AC-003 Exact annotations with executable YAML unchanged ruby evidence/verify.rb --committed Ruby 2.6.10, Psych 3.1.0, isolated review packet Exact scoped replacements and equality 2/2 files; 3/3 lines; all invariants pass PASS
V2 AC-004 Hosted checks on this exact head Inspect this draft's checks GitHub Actions Applicable checks succeed Results not yet collected NOT VERIFIED

Security and compatibility

Documentation annotation only. No dependencies, permissions, credentials, data flows, or runtime behavior change. The diff and commit identity were inspected for public-safe content. No CHANGELOG entry or behavior-documentation update is needed because only explanatory comments change.

Known limitations

Runtime suites, build, coverage, and dependency audits were not rerun for this comment-only change; no runtime test result is claimed. Hosted CI is separate from local equality proof. This is a draft, not merge-ready.

Risk and rollback

Low-risk annotation correction. Roll back through an ordinary revert of this single commit. There is no migration or release action.

Product review handoff

  • Implementation/publication owner: @PeterGuy326
  • Automated pre-review result: independent local replay recorded in R1; no human approval implied.
  • Human final review: PENDING; no human review requested by this publication.
  • Merge ledger owner: @PeterGuy326
  • Product reviewer: @PeterGuy326
  • Milestone or release packet: N/A: bounded documentation annotation maintenance
  • Merge, CI, release, and model judgment do not accept or close the Issue: acknowledged

Annotate the existing cdf488f595d80d6e07e03d4674febd5ab45fa938 pin as v4.37.9. The action SHA and executable workflow configuration are unchanged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant