Skip to content

test: verify regression workflow fix - #21

Closed
gontzess wants to merge 1 commit into
mainfrom
gontzess/test-regression-workflow
Closed

test: verify regression workflow fix#21
gontzess wants to merge 1 commit into
mainfrom
gontzess/test-regression-workflow

Conversation

@gontzess

@gontzess gontzess commented Mar 3, 2026

Copy link
Copy Markdown
Contributor

Test PR — points verify.yaml at github-workflows branch gontzess/move-regression-workflow-local to validate the regression workflow fix before merging. Close without merging.

Summary by CodeRabbit

  • Chores
    • Updated continuous integration workflow configuration to use an alternative workflow version.

@gontzess
gontzess requested a review from a team March 3, 2026 19:28
@github-actions

github-actions Bot commented Mar 3, 2026

Copy link
Copy Markdown
Contributor

Claude Code is working…

I'll analyze this and get back to you.

View job run

@coderabbitai

coderabbitai Bot commented Mar 3, 2026

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

The verify workflow configuration is updated to reference a feature branch of the shared workflow repository instead of the v4 release tag, allowing testing of changes from the branch.

Changes

Cohort / File(s) Summary
Workflow Configuration
.github/workflows/verify.yaml
Updated verify job to use feature branch gontzess/move-regression-workflow-local instead of release tag v4 for the shared workflow reference.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 A branch swap, swift and light,
From v4's tag to feature's flight,
Verify shall test the way,
With gontzess's branch in play! ✨

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'test: verify regression workflow fix' clearly and concisely summarizes the main change—updating the verify workflow to test a regression fix before merging.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch gontzess/test-regression-workflow

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/verify.yaml:
- Line 13: The reusable workflow reference currently uses a mutable branch ref
("uses:
ConductorOne/github-workflows/.github/workflows/verify.yaml@gontzess/move-regression-workflow-local");
update it to an immutable ref (a commit SHA or a signed/tagged release) by
replacing the branch name with the corresponding commit SHA or a release tag so
the workflow is pinned to a fixed, auditable revision before merging.

ℹ️ Review info

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 4fea165 and dd46e38.

📒 Files selected for processing (1)
  • .github/workflows/verify.yaml

jobs:
verify:
uses: ConductorOne/github-workflows/.github/workflows/verify.yaml@v4
uses: ConductorOne/github-workflows/.github/workflows/verify.yaml@gontzess/move-regression-workflow-local

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

cat -n .github/workflows/verify.yaml

Repository: ConductorOne/baton-mysql

Length of output: 1874


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Verify reusable workflow refs are immutable SHAs in repo workflows.
fd -t f '.*\.ya?ml$' .github/workflows | while read -r file; do
  rg -nP '^\s*uses:\s*ConductorOne/github-workflows/\.github/workflows/[^@]+@([^\s#]+)' "$file" \
  | while IFS=: read -r path line content; do
      ref="$(printf '%s' "$content" | sed -E 's/.*@([^[:space:]]+).*/\1/')"
      if [[ ! "$ref" =~ ^[0-9a-fA-F]{40}$ ]]; then
        echo "$path:Line $line uses non-immutable ref: $ref"
      fi
    done
done

Repository: ConductorOne/baton-mysql

Length of output: 1874


Pin the reusable workflow to an immutable ref before any merge.

Line 13 uses a branch ref (@gontzess/move-regression-workflow-local), which is mutable. If this PR is merged by mistake, the verify workflow becomes non-deterministic and weakens CI supply-chain guarantees.

Suggested change
-    uses: ConductorOne/github-workflows/.github/workflows/verify.yaml@gontzess/move-regression-workflow-local
+    uses: ConductorOne/github-workflows/.github/workflows/verify.yaml@<commit-sha>
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/verify.yaml at line 13, The reusable workflow reference
currently uses a mutable branch ref ("uses:
ConductorOne/github-workflows/.github/workflows/verify.yaml@gontzess/move-regression-workflow-local");
update it to an immutable ref (a commit SHA or a signed/tagged release) by
replacing the branch name with the corresponding commit SHA or a release tag so
the workflow is pinned to a fixed, auditable revision before merging.

@gontzess gontzess closed this Mar 3, 2026
@gontzess
gontzess deleted the gontzess/test-regression-workflow branch March 3, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant