Per the updated handbook convention (engineering-handbook PR #18),
reusable-workflow references use full commit SHA pins with a '# main'
comment instead of the mutable @main branch ref. Templates now ship
pinned so new repos start convention-compliant; Dependabot advances
the pin after instantiation. Commented usage examples in ci-static and
ci-typescript-frontend use the <full-commit-sha> placeholder form.
Add job-level concurrency (cancel-in-progress) to all four ci-python-app
jobs, matching the ci-python-sam idiom. Per-job group keys include
github.job so the parallel jobs in a single run do not share a group.
Replace sam-deploy starter-template stack-name: $default-branch (which
GitHub substitutes to the literal branch name main) with a
REPLACE-ME-stack-name placeholder, and point cfn-role-arn at the real
shared github-cfn-execution-role.
actions/checkout v7.0.0 (2026-06-18) is internally an ESM rebuild plus
one behavioral change: it blocks checking out a fork PR head ref under
pull_request_target / workflow_run (PR #2454). No Sea Haven workflow uses
those triggers, so there is no reachable behavior change. The Node 24
runtime requirement already landed at v6, so v6 -> v7 carries no new
runner requirement. All runners here are GitHub-hosted (ubuntu, macos).
Covers all 16 checkout pins across 12 reusable/standalone workflows plus
the dependency-review workflow-template scaffold. Consumers on @main pick
this up automatically on merge.
Add callable-labeler.yaml, a reusable workflow that carries the label
rules inline as the single source of truth and writes them to the runner
at execution time, so caller repos need only a short caller workflow and
no per-repo labeler.yml. Triggered by callers on pull_request (private org
takes no fork PRs); requires contents:read + pull-requests:write +
issues:write on every caller so labeler@v5 can create missing labels.
Remove the workflow-templates/labeler.yml starter it supersedes (no
ruleset workflows-rule or compliance-audit reference depends on it).
Add the repo's own dependabot.yml (github-actions, weekly, grouped
minor+patch) to keep the action pins current per the Pinning Principle.