The inline ci/ci aggregator green-lit the org-required check when a
needed job was SKIPPED (result 'skipped' is neither 'failure' nor
'cancelled'). Treat 'skipped' as a failure so a conditionally-skipped
required job can no longer pass the required check without running.
Contained inline fix; the audit's shared callable-ci-aggregate.yaml
(Stub 4) is deferred as it needs a new org-wide reusable workflow.
exec-aide's caller jobs are named python/typescript, so the org ruleset's
required 'ci / ci' status check never reported here and every PR was
merge-blocked for non-admins. The aggregator needs all real CI jobs and
fails if any failed or was cancelled.
* Add dependency-review caller workflow
Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.
* chore: retrigger checks
* chore: retrigger dep review (post-fix)
* chore: retrigger ci
* chore: retrigger CI after concurrency fix
* Add CI workflow and apply ruff formatting
* Disable cdk synth — PythonFunction requires Docker arm64 builds
The PythonFunction construct bundles via Docker with --platform
linux/arm64, which fails on GitHub Actions x86 runners. tsc --noEmit
still runs and catches TypeScript errors.