ci: enforce workflow policy - #186
Conversation
|
@francoischalifour could you review this? I picked you because recent workflow-path history points to your ownership of the release and semantic-title automation. CI is pending. The main review focus is preserving the Node/Bun trusted-publishing setup while pinning the actions and runner images. |
|
@francoischalifour could you take a look when you have capacity? This workflow-policy change is green and has been awaiting review since the August 10 request. The review focus is preserving the Node/Bun trusted-publishing setup while keeping the action pins and Ubuntu 24.04 runner updates correctly scoped. |
|
@francoischalifour could you review this when you have capacity? This scoped change is still green and has had no reviewer activity for at least three days. The review focus is preserving trusted publishing while keeping runner and immutable-action changes correctly scoped.. |
|
@francoischalifour follow-up: this is still green and unreviewed after three days. Could you review that the trusted-publishing workflow remains intact and the runner/action-pin changes stay correctly scoped? |
|
@francoischalifour follow-up: this CI policy update remains green and unreviewed after three days. Could you review that the trusted-publishing behavior is preserved and the runner/action-pin changes remain scoped? |
|
@francoischalifour follow-up: this CI policy update remains green and unreviewed after three days. Could you review that trusted-publishing behavior is preserved and the runner/action-pin changes remain correctly scoped? |
|
@francoischalifour could you review this CI policy update? The scope is preserving trusted publishing while applying runner and action-pin policy. |
Summary
ubuntu-24.04.node-versionand.bun-versionruntime contractsImpact
This is workflow-only hardening. It does not change the SDK packages, release contract, or runtime behavior. The existing community-file PR #180 modifies a separate legacy semantic-workflow path; it remains unsafe to merge because it would add a duplicate noncompliant check.
Verification
bash /root/.openclaw/workspace/scripts/validate-workflow-policy.sh /root/.openclaw/workspace/code/altertable-jsgit diff --checkbun run lintbun run test