From 69b28c6f3ae41d5f11c64d3818030ddde13adefe Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 27 Jul 2026 15:38:18 -0400 Subject: [PATCH] ci: pin workflow-template refs to commit SHA Per the updated handbook convention (engineering-handbook PR #18), reusable-workflow references use full commit SHA pins with a '# main' comment instead of the mutable @main branch ref. Templates now ship pinned so new repos start convention-compliant; Dependabot advances the pin after instantiation. Commented usage examples in ci-static and ci-typescript-frontend use the placeholder form. --- .github/workflows/ci-static.yaml | 2 +- .github/workflows/ci-typescript-frontend.yaml | 2 +- workflow-templates/cdk-deploy.yml | 2 +- workflow-templates/ci-node.yml | 2 +- workflow-templates/ci-python.yml | 2 +- workflow-templates/dependency-review.yml | 2 +- workflow-templates/labeler.yml | 2 +- workflow-templates/sam-deploy.yml | 2 +- 8 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/ci-static.yaml b/.github/workflows/ci-static.yaml index dfd9ae5..b03d5db 100644 --- a/.github/workflows/ci-static.yaml +++ b/.github/workflows/ci-static.yaml @@ -15,7 +15,7 @@ name: CI — Static Site # Caller example (build mode): # jobs: # ci: -# uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@main +# uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@ # main # with: # build-command: "npx @11ty/eleventy" # check-dir: "_site" diff --git a/.github/workflows/ci-typescript-frontend.yaml b/.github/workflows/ci-typescript-frontend.yaml index 3103bfd..18f81bf 100644 --- a/.github/workflows/ci-typescript-frontend.yaml +++ b/.github/workflows/ci-typescript-frontend.yaml @@ -13,7 +13,7 @@ name: CI — TypeScript Frontend # Caller example: # jobs: # ci: -# uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@main +# uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@ # main # with: # node-version: "24" diff --git a/workflow-templates/cdk-deploy.yml b/workflow-templates/cdk-deploy.yml index e092d91..e39cacd 100644 --- a/workflow-templates/cdk-deploy.yml +++ b/workflow-templates/cdk-deploy.yml @@ -5,6 +5,6 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} diff --git a/workflow-templates/ci-node.yml b/workflow-templates/ci-node.yml index eef89ac..adca81b 100644 --- a/workflow-templates/ci-node.yml +++ b/workflow-templates/ci-node.yml @@ -5,4 +5,4 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main diff --git a/workflow-templates/ci-python.yml b/workflow-templates/ci-python.yml index 67c697d..9ae9f03 100644 --- a/workflow-templates/ci-python.yml +++ b/workflow-templates/ci-python.yml @@ -5,6 +5,6 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@555d07c3a240689a81668026787eba089df4c975 # main with: run-tests: true diff --git a/workflow-templates/dependency-review.yml b/workflow-templates/dependency-review.yml index 64eb33d..36c0f4e 100644 --- a/workflow-templates/dependency-review.yml +++ b/workflow-templates/dependency-review.yml @@ -8,4 +8,4 @@ permissions: jobs: dependency-review: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main + uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@555d07c3a240689a81668026787eba089df4c975 # main diff --git a/workflow-templates/labeler.yml b/workflow-templates/labeler.yml index 5914610..d07b5b8 100644 --- a/workflow-templates/labeler.yml +++ b/workflow-templates/labeler.yml @@ -13,4 +13,4 @@ permissions: jobs: label: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main + uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@555d07c3a240689a81668026787eba089df4c975 # main diff --git a/workflow-templates/sam-deploy.yml b/workflow-templates/sam-deploy.yml index c734753..f83201d 100644 --- a/workflow-templates/sam-deploy.yml +++ b/workflow-templates/sam-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main + uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@555d07c3a240689a81668026787eba089df4c975 # main with: # Required: the CloudFormation stack name (kebab-case, matches repo name). # NOTE: this is a literal placeholder on purpose — starter-workflow variables