chore: update repo-governance actions to v0.5.0#119
Open
t3chn wants to merge 1 commit into
Open
Conversation
Why: - Roll out the v0.5.0 PR Intake Gate release to Signum. - v0.5.0 includes strict root-level policy key validation, and the checked policy was compatible before updating the ref. What changed: - Update the pr-intake-gate action ref from the v0.4.0 commit to the v0.5.0 commit SHA. - Update the checked-in action pin fixture to match the new expected repo-governance pin. - Leave local policy semantics unchanged. Testing: - bash tests/test-github-action-pinning.sh - bash scripts/run-deterministic-tests.sh - git diff --check Risk: - narrow - workflow pin and matching pin fixture only.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates only repo-governance action refs to the v0.5.0 commit SHA.
v0.5.0 adds strict root-level PR Intake policy validation: unknown top-level policy keys now fail fast.
Local policy compatibility was checked before updating refs. Policy semantics are unchanged.
Runtime proof requires merge because pull_request_target uses the base workflow.
Tests run: