diff --git a/.github/workflows/proof-pr.yml b/.github/workflows/proof-pr.yml index fce142b..31b3222 100644 --- a/.github/workflows/proof-pr.yml +++ b/.github/workflows/proof-pr.yml @@ -9,10 +9,10 @@ permissions: jobs: proof: - uses: saagpatel/proof-pr/.github/workflows/proof-pr-receipt.yml@v0.2.12 + uses: saagpatel/proof-pr/.github/workflows/proof-pr-receipt.yml@v0.2.13 with: receipt_path: proof-pr.json - proof_pr_ref: v0.2.12 + proof_pr_ref: v0.2.13 check_public_git_metadata: true public_git_metadata_mode: introduced artifact_name: github-repo-auditor-proof-pr diff --git a/docs/proof-pr-dogfood.md b/docs/proof-pr-dogfood.md index cb5949c..ca17834 100644 --- a/docs/proof-pr-dogfood.md +++ b/docs/proof-pr-dogfood.md @@ -12,7 +12,7 @@ environment and render the proof block from a generated receipt: ```bash python3 -m venv /tmp/gra-proof-pr-venv /tmp/gra-proof-pr-venv/bin/python -m pip install \ - git+https://github.com/saagpatel/proof-pr.git@v0.2.12 + git+https://github.com/saagpatel/proof-pr.git@v0.2.13 /tmp/gra-proof-pr-venv/bin/proof-pr init \ --cwd . \ --tier T1 \ @@ -38,6 +38,8 @@ The reusable workflow writes the normal hygiene report plus a focused public git metadata fix block to the GitHub job summary when that finding exists. If no focused fix is needed, the block prints a clean no-action-needed note. Use `proof-pr examples` when choosing which receipt pattern to copy. +The reusable workflow uploads `proof-pr-summary.md` with the rendered proof +block alongside the receipt and any configured proof artifacts. For GithubRepoAuditor, keep the risk tier honest: