Non-Blocking Review Concern: Assistant workflow now references a mutable tag instead of a pinned commit SHA
Source: analysis of diff (no reviewer flagged this)
Location: .github/workflows/claude.yml:23
PR: #112 — fix(ci): repoint assistant workflow from stale SHA to @v3.1.2 (#112)
Date: 2026-08-17
What was flagged
The reference changed from a full commit SHA to the @v3.1.2 tag. Since this is a first-party smartwatermelon-owned reusable workflow, tag references are consistent with the repo's existing conventions and not a supply-chain concern. Noted only because tags are force-updatable in this org's release process, so v3.1.2 is not guaranteed immutable — worth confirming that point releases are treated as frozen rather than floating.
Context
This issue was automatically created from a non-blocking concern identified
during pre-merge review of PR #112. It was safe to merge but worth tracking.
Created by lib-review-issues.sh
Non-Blocking Review Concern: Assistant workflow now references a mutable tag instead of a pinned commit SHA
Source: analysis of diff (no reviewer flagged this)
Location:
.github/workflows/claude.yml:23PR: #112 — fix(ci): repoint assistant workflow from stale SHA to @v3.1.2 (#112)
Date: 2026-08-17
What was flagged
The reference changed from a full commit SHA to the
@v3.1.2tag. Since this is a first-partysmartwatermelon-owned reusable workflow, tag references are consistent with the repo's existing conventions and not a supply-chain concern. Noted only because tags are force-updatable in this org's release process, sov3.1.2is not guaranteed immutable — worth confirming that point releases are treated as frozen rather than floating.Context
This issue was automatically created from a non-blocking concern identified
during pre-merge review of PR #112. It was safe to merge but worth tracking.
Created by lib-review-issues.sh