Skip to content

chore: sync workflow templates - #627

Merged
stranske merged 1 commit into
mainfrom
sync/workflows-57b9e3dbcb23
Jun 26, 2026
Merged

chore: sync workflow templates#627
stranske merged 1 commit into
mainfrom
sync/workflows-57b9e3dbcb23

Conversation

@stranske

@stranske stranske commented Jun 26, 2026

Copy link
Copy Markdown
Owner

Sync Summary

Files Updated

  • agents-guard.yml: Agents guard - enforces agents workflow protections (Health 45)
  • maint-76-claude-code-review.yml: Claude Code review (opt-in) - runs only on labeled PRs or manual dispatch

Files Skipped

  • pr-00-gate.yml: File exists and sync_mode is create_only
  • ci.yml: File exists and sync_mode is create_only
  • renovate.json: File exists and sync_mode is create_only
  • cross-repo-smoke.yml: File exists and sync_mode is create_only
  • llm_slots.json: None

Review Checklist

  • CI passes with updated workflows
  • No repo-specific customizations were overwritten

Source: stranske/Workflows
Source SHA: cd5687d7ae00a31b9cb6ddbf94cfb94c0e4fdf69
Template hash: 57b9e3dbcb23
Sync branch: sync/workflows-57b9e3dbcb23
Consumer repo: stranske/Pension-Data
Manifest: .github/sync-manifest.yml

Summary by CodeRabbit

  • Chores
    • Updated workflow dependencies to newer pinned revisions for automated checks and code review tasks.
    • Improved consistency of CI workflow runs by refreshing the versions used in multiple paths.

Automated sync from stranske/Workflows
Template hash: 57b9e3dbcb23

Changes synced from sync-manifest.yml
@stranske stranske added sync Automated sync from Workflows automated Automated sync from Workflows labels Jun 26, 2026
@stranske
stranske temporarily deployed to agent-standard June 26, 2026 02:34 — with GitHub Actions Inactive
@stranske
stranske temporarily deployed to agent-standard June 26, 2026 02:34 — with GitHub Actions Inactive
@coderabbitai

coderabbitai Bot commented Jun 26, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This PR updates pinned GitHub Actions revisions in two workflows: the agents guard fallback setup-api-client steps and the Claude Code Review step.

Changes

Workflow action pin updates

Layer / File(s) Summary
Agents guard fallback pin
\.github/workflows/agents-guard.yml
The pull_request_target and pull_request fallback steps now reference a different pinned setup-api-client action revision.
Claude Code Review pin
\.github/workflows/maint-76-claude-code-review.yml
The Run Claude Code Review step now references a different pinned anthropics/claude-code-action revision.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • stranske/Pension-Data#584: Updates the same setup-api-client pinned revision in .github/workflows/agents-guard.yml.
  • stranske/Pension-Data#591: Updates the same pinned anthropics/claude-code-action reference in .github/workflows/maint-76-claude-code-review.yml.
  • stranske/Pension-Data#569: Also repins workflow actions in both agents-guard.yml and maint-76-claude-code-review.yml.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the PR as a sync of workflow templates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sync/workflows-57b9e3dbcb23

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Keepalive Loop Reporter. Do not edit.

@github-actions

github-actions Bot commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Agents Gate Followups. Do not edit.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/agents-guard.yml:
- Line 114: The fallback action pin in agents-guard is out of sync with the
upstream stranske/Workflows template. Update the referenced setup-api-client
step to match the same commit pinned in the source agents-guard.yml template, or
explicitly document why this repository intentionally diverges; use the
setup-api-client reference in agents-guard.yml to locate the stale pin.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 46deaceb-aab7-44e0-9c50-7521029ad66a

📥 Commits

Reviewing files that changed from the base of the PR and between cc4e12d and aef90fa.

📒 Files selected for processing (2)
  • .github/workflows/agents-guard.yml
  • .github/workflows/maint-76-claude-code-review.yml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • stranske/Workflows (auto-detected)
📜 Review details
🧰 Additional context used
📓 Path-based instructions (2)
**/.github/workflows/*.yml

📄 CodeRabbit inference engine (CLAUDE.md)

Reference reusable workflows from stranske/Workflows with @main unless intentionally pinning to an exact commit SHA for a controlled reason.

Reference reusable workflows with @main unless intentionally pinning to an exact commit SHA for a controlled reason.

Files:

  • .github/workflows/maint-76-claude-code-review.yml
  • .github/workflows/agents-guard.yml
{**/.github/workflows/agents-*.yml,**/.github/workflows/autofix.yml,**/.github/codex/**}

📄 CodeRabbit inference engine (CLAUDE.md)

For synced workflows, prompts, scripts, and consumer docs (e.g., agents-*.yml, autofix.yml, .github/codex/ prompts) — fix them in stranske/Workflows first, not locally in the consumer repo.

Files:

  • .github/workflows/agents-guard.yml
🔀 Multi-repo context stranske/Workflows

Linked repositories findings

stranske/Workflows

  • .github/workflows/agents-guard.yml:103,173 — both pull_request_target and pull_request fallback steps use the pinned external action stranske/Workflows/.github/actions/setup-api-client@6c3391d38bbc20a4577ac42b9aa6c9dc4e462c09. Since this workflow is the source template for the sync, any repin here is directly relevant to the generated consumer workflow and should preserve the same inputs (secrets, github_token).
  • .github/workflows/agents-guard.yml:64-93,134-163 — the workflow has a local-vs-fallback split for setup-api-client, guarded by file existence checks. That means the pin only matters when the local action is absent; consumers rely on the fallback being behaviorally compatible.
  • .github/workflows/*.yml — broad search shows setup-api-client is used widely across many workflows (reusable-*, maint-*, health-*, agents-*). This makes the pinned revision in the fallback path a shared dependency surface, not an isolated change.

No matching maint-76-claude-code-review.yml file exists in stranske/Workflows, so I couldn’t validate that workflow here. [::stranske/Workflows::]

🔇 Additional comments (1)
.github/workflows/maint-76-claude-code-review.yml (1)

192-192: 🔒 Security & Privacy

No action needed on the pin The @521136812280ae7ef256e06045655b9da02793f0 # v1 reference matches the v1 tag. There’s no matching maint-76-claude-code-review.yml in stranske/Workflows, so this workflow doesn’t appear to be synced from that repo.

			> Likely an incorrect or invalid review comment.

Comment thread .github/workflows/agents-guard.yml
@stranske
stranske merged commit fdf6897 into main Jun 26, 2026
95 of 101 checks passed
@stranske
stranske deleted the sync/workflows-57b9e3dbcb23 branch June 26, 2026 04:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated sync from Workflows sync Automated sync from Workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant