Skip to content

fix(ci): restore allowed Trunk action pin - #502

Merged
KooshaPari merged 1 commit into
mainfrom
fix/trunk-action-policy-pin-20260805
Aug 7, 2026
Merged

KooshaPari merged 1 commit into
mainfrom
fix/trunk-action-policy-pin-20260805

Conversation

@KooshaPari

@KooshaPari KooshaPari commented Aug 5, 2026 •

Copy link
Copy Markdown
Owner

User description

Scope

Restores only the two trunk-io/trunk-action references in .github/workflows/trunk-check.yml to the repository allowlisted immutable SHA.

Provenance

  • Base: 92fafe865c5291aae2c17c1b9c88fc0a6a47407f
  • Prior permitted/green Trunk workflow reference: 04ba50e7658c81db7356da96657e6e77f220bfa3
  • Repository Actions policy: selected actions with full-SHA pinning required.

Validation

  • actionlint -oneline .github/workflows/trunk-check.yml
  • Ruby YAML parse
  • git diff --check
  • exact one-file, two-reference diff

This PR deliberately does not change CI, Cross-Platform, Scorecard, action policy, or OmniRoute #501.


CodeAnt-AI Description

Restore the approved Trunk action version for CI checks

What Changed

  • Trunk lint and formatting checks now use the repository-approved immutable action reference
  • Scheduled Trunk upgrades use the same approved reference

Impact

✅ CI checks comply with the repository action policy
✅ Scheduled Trunk upgrades remain available

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Chores
    • Updated automated code-quality checks to use the pinned 1.0.4 release.

Copilot AI lite review requested due to automatic review settings August 5, 2026 09:38
@codeant-ai

codeant-ai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 0f6313d Aug 05, 2026 · 09:38 09:39

@codeant-ai

codeant-ai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@codeant-ai codeant-ai Bot added the size:XS This PR changes 0-9 lines, ignoring generated files label Aug 5, 2026
@coderabbitai

coderabbitai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

.coderabbit.yaml has unrecognized properties

CodeRabbit is using all valid settings from your configuration. Unrecognized properties (listed below) have been ignored and may indicate typos or deprecated fields that can be removed.

⚠️ Parsing warnings (1)
Validation error: Unrecognized key: "review"
⚙️ Configuration instructions
  • Please see the configuration documentation for more information.
  • You can also validate your configuration using the online YAML validator.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 1360a29b-b573-414f-930f-092a2bab781d

📥 Commits

Reviewing files that changed from the base of the PR and between 92fafe8 and 0f6313d.

📒 Files selected for processing (1)
  • .github/workflows/trunk-check.yml

📝 Walkthrough

Walkthrough

The workflow updates the pinned trunk-io/trunk-action commit for the standard Trunk Check and scheduled Trunk Upgrade steps.

Changes

Trunk Action update

Layer / File(s) Summary
Update Trunk Action pin
.github/workflows/trunk-check.yml
Both Trunk Action workflow steps now reference the updated pinned commit for version 1.0.4.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Suggested reviewers: copilot

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes restoring the approved Trunk action pin in CI.
Description check ✅ Passed The description explains the scope, rationale, validation steps, impact, and explicitly lists excluded changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/trunk-action-policy-pin-20260805

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Aug 5, 2026

Copy link
Copy Markdown

@kilo-code-bot

kilo-code-bot Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (1 file)
  • .github/workflows/trunk-check.yml - Restored allowed Trunk action SHA pin (2 lines changed)

Reviewed by step-3.7-flash · Input: 92.4K · Output: 1.7K · Cached: 570.8K

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown

L17 Latency Budget Report

--- Latency Budget Summary ---
  Total endpoints checked: 0
  Passed: 0
  Warnings: 0
  Failures: 0

Checked against: budgets/rest-endpoints.yaml.

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown

L17 Latency Regression Report

No trace file available — cannot compute regression

Threshold: 10% p99 regression.

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/trunk-io/trunk-action 04ba50e7658c81db7356da96657e6e77f220bfa3 🟢 6.9
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 34 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
Dependency-Update-Tool🟢 10update tool detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Vulnerabilities🟢 100 existing vulnerabilities detected
Signed-Releases⚠️ -1no releases found
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST🟢 7SAST tool detected but not run on all commits
CI-Tests⚠️ 28 out of 30 merged PRs checked by a CI test -- score normalized to 2
Contributors🟢 10project has 4 contributing companies or organizations

Scanned Files

  • .github/workflows/trunk-check.yml

@KooshaPari
KooshaPari merged commit 87bcc4a into main Aug 7, 2026
24 of 30 checks passed
@KooshaPari
KooshaPari deleted the fix/trunk-action-policy-pin-20260805 branch August 7, 2026 06:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants