ci: pin workflow-template refs to commit SHA

Per the updated handbook convention (engineering-handbook PR #18),
reusable-workflow references use full commit SHA pins with a '# main'
comment instead of the mutable @main branch ref. Templates now ship
pinned so new repos start convention-compliant; Dependabot advances
the pin after instantiation. Commented usage examples in ci-static and
ci-typescript-frontend use the <full-commit-sha> placeholder form.
This commit is contained in:
Adam Moussa 2026-07-27 15:38:18 -04:00
parent 555d07c3a2
commit 69b28c6f3a
No known key found for this signature in database
8 changed files with 8 additions and 8 deletions

View file

@ -15,7 +15,7 @@ name: CI — Static Site
# Caller example (build mode): # Caller example (build mode):
# jobs: # jobs:
# ci: # ci:
# uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@main # uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@<full-commit-sha> # main
# with: # with:
# build-command: "npx @11ty/eleventy" # build-command: "npx @11ty/eleventy"
# check-dir: "_site" # check-dir: "_site"

View file

@ -13,7 +13,7 @@ name: CI — TypeScript Frontend
# Caller example: # Caller example:
# jobs: # jobs:
# ci: # ci:
# uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@main # uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@<full-commit-sha> # main
# with: # with:
# node-version: "24" # node-version: "24"

View file

@ -5,6 +5,6 @@ on:
jobs: jobs:
deploy: deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
secrets: secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}

View file

@ -5,4 +5,4 @@ on:
jobs: jobs:
ci: ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main

View file

@ -5,6 +5,6 @@ on:
jobs: jobs:
ci: ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with: with:
run-tests: true run-tests: true

View file

@ -8,4 +8,4 @@ permissions:
jobs: jobs:
dependency-review: dependency-review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@555d07c3a240689a81668026787eba089df4c975 # main

View file

@ -13,4 +13,4 @@ permissions:
jobs: jobs:
label: label:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@555d07c3a240689a81668026787eba089df4c975 # main

View file

@ -5,7 +5,7 @@ on:
jobs: jobs:
deploy: deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with: with:
# Required: the CloudFormation stack name (kebab-case, matches repo name). # Required: the CloudFormation stack name (kebab-case, matches repo name).
# NOTE: this is a literal placeholder on purpose — starter-workflow variables # NOTE: this is a literal placeholder on purpose — starter-workflow variables