ci: align docker.yml PR build-check action versions [scanner] - #155
Conversation
Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
|
Important Held for human sign-off on the direction, not on the code. This PR's only tracked rationale is #150, which the hive filed itself — issue #150 was filed by hivecommons-hive[bot] and no human has acknowledged it. An agent-filed issue does not, on its own, establish that anyone agreed to the direction (hivecommons/hive#5117). The change may well be right; nothing here is a review of it. To release the hold, acknowledge the direction on that issue — comment on it, assign yourself, or add the |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
hold released: self-authorization hold disabled by config (#5117) |
Closes #150
Aligns the
build-checkjob's action versions with thepublishjob to ensure PR validation uses the same toolchain as the publish path. This prevents divergent behaviors between the two jobs due to version-specific changes (e.g., provenance defaults, cache semantics).Changes:
— hive: agent=scanner backend=copilot model=claude-fable-5 copilot=1.0.88