Skip to content

ci: use shared workflow v1 channel - #58

Merged
VinnyBarton merged 1 commit into
mainfrom
ci/use-shared-workflows-v1
Oct 7, 2026
Merged

VinnyBarton merged 1 commit into
mainfrom
ci/use-shared-workflows-v1

Conversation

@VinnyBarton

Copy link
Copy Markdown
Collaborator

Summary

  • replace all nine supply-chain-workflows commit pins with the managed v1 compatibility channel
  • cover build, lint, security, SBOM lifecycle, Interlynk publication, ReARM, and release workflows
  • supersede fix: use least-privilege shared workflows #57, which updated the same references to another fixed SHA

Validation

  • verified v1 resolves to validated shared-workflow commit 130e17b0766a2fc61f1304a68f0dd6bca78520c0
  • Actionlint v1.7.7 and ShellCheck passed across every repository workflow
  • git diff --check passed

Trust model

The v1 reference is intentionally mutable. It is maintained by supply-chain-workflows validation automation and will receive backward-compatible changes without consumer-side dependency PRs. This repository therefore trusts validated v1 changes merged in the shared-workflow repository.

@VinnyBarton
VinnyBarton merged commit 02e74c1 into main Oct 7, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant