fix(oidc): roll forward trusted central workflow source - #442
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
Changes중앙 워크플로 신뢰 설정 갱신
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to The PR only advances the trusted workflow source commit without changing the workflow bytes or trust scope. No actionable merge-blocking risk remains once the required checks complete successfully. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Scope
Restore Noema's immutable OIDC reusable-workflow source trust after read-only central
.githubprotectedmainadvanced from731af58e954901c4f1cc853231c592abb1eaf617todd58a88391e44a32fb399f7407f508d8e73cc1c7.The trusted
.github/workflows/noema-review.ymlblob is unchanged at59b25e343444d0b97fc1c7ba33cb15543dd70102, so this is a source-commit roll-forward, not acceptance of changed reviewer workflow bytes or a widened workflow ref.Test-first repair
4e031a60dab643ee70dc612e7d37786d7b655dbb: executable trust regression requires central source commitdd58a883...whilewrangler.tomlstill trusts predecessor731af58....eaf3e158afc513f1755f1ac6e3443f965c72e8c9: update onlyALLOWED_WORKFLOW_SHAto the freshly audited central source commit.11cd11c2ae0d6cf0488a1b130fc5ce903de344fa: merge protected main80925420bb14c673510e0ed206257befa55da7a9without changing the two reviewed feature blobs.test/trusted-workflow-source-rollforward.test.tsandwrangler.toml.Issuer, audience, repository owner, exact workflow ref, cryptographic source-SHA comparison, replay protection and GitHub App credential scope are unchanged. Central
.githubremains read-only from this writer.Current identity and evidence
80925420bb14c673510e0ed206257befa55da7a911cd11c2ae0d6cf0488a1b130fc5ce903de344fadd58a88391e44a32fb399f7407f508d8e73cc1c759b25e343444d0b97fc1c7ba33cb15543dd7010232498957233: queued32498957247: queued32498957203: queuedFresh terminal-success evidence on this unchanged exact head is required before Ready/merge. Pending, predecessor or stale evidence is non-passing.
Summary by CodeRabbit