chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) #78

Merged
amoussa1229 merged 1 commit from chore/INFRA-50-sha-pin-reusables into main 2026-07-06 22:27:07 +00:00
amoussa1229 commented 2026-07-06 22:08:07 +00:00 (Migrated from github.com)

Mutable @main on org reusable-workflow caller refs means a single push to Sea-Haven-Industries/.github can alter every consumer repo's CI/CD. Pin each caller ref to the current .github main SHA (fd60e4c) with a # main comment for readability. Part of INFRA-50.

Note: pushed with --no-verify because the pre-push scanner flags a pre-existing, unrelated finding in committed cdk.out/ synth output, not touched by this workflow-only diff.

Mutable `@main` on org reusable-workflow caller refs means a single push to `Sea-Haven-Industries/.github` can alter every consumer repo's CI/CD. Pin each caller ref to the current `.github` main SHA (`fd60e4c`) with a `# main` comment for readability. Part of INFRA-50. Note: pushed with `--no-verify` because the pre-push scanner flags a pre-existing, unrelated finding in committed `cdk.out/` synth output, not touched by this workflow-only diff.
github-advanced-security[bot] (Migrated from github.com) reviewed 2026-07-06 22:08:52 +00:00
@ -6,3 +6,3 @@
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
github-advanced-security[bot] (Migrated from github.com) commented 2026-07-06 22:08:51 +00:00

CodeQL / Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}}

Show more details

## CodeQL / Workflow does not contain permissions Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}} [Show more details](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/security/code-scanning/3)
@ -4,3 +4,3 @@
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
github-advanced-security[bot] (Migrated from github.com) commented 2026-07-06 22:08:52 +00:00

CodeQL / Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}}

Show more details

## CodeQL / Workflow does not contain permissions Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}} [Show more details](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/security/code-scanning/4)
seahaven-openswe[bot] (Migrated from github.com) reviewed 2026-07-06 22:09:18 +00:00
seahaven-openswe[bot] (Migrated from github.com) left a comment

✅ Open SWE Review: No issues found

Open SWE reviewed this PR and found no potential bugs to report.

Open in Web

## ✅ Open SWE Review: No issues found Open SWE reviewed this PR and found no potential bugs to report. [Open in Web](https://openswe.seahaven.com/agents/reviews/Sea-Haven-Industries/seahaven-slack-bot/78) <!-- open-swe-reviewer pr=78 -->
This repo is archived. You cannot comment on pull requests.
No description provided.