chore: update tend workflows (0.3.5 → 0.3.6) - #964
Conversation
Deploying mouseterm with
|
| Latest commit: |
3f9c269
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://b907d75f.mouseterm.pages.dev |
| Branch Preview URL: | https://tend-update-workflows.mouseterm.pages.dev |
dormouse-bot
left a comment
There was a problem hiding this comment.
docs/specs/security-ci.md no longer matches these workflows. "Upstream compromise" says tend-mention and tend-notifications run astral-sh/setup-uv@<tag>, and "GitHub Actions Policies" says tend-*.yaml is generated "with tag pins". After this regen, actions/checkout and setup-uv are commit-pinned and the uv download is checksum-verified; only max-sixty/tend/claude@<version> is still a tag. The ci-and-secrets audit reads that spec, so it would describe the setup-uv acceptance as a residual that no longer exists. The matching paragraph in security-ci.rationale.md ("Why the mutable upstream tag is accepted") has the same drift. I'll push the spec update to this branch.
I checked the new pins against upstream. 3d3c42e… is actions/checkout v7.0.1 and c18668a… is setup-uv v10.2.0. Both checksums match the .sha256 files on the uv 0.12.19 release for x86_64 and aarch64 Linux.
Regenerates the Tend workflows with tend 0.3.6 (from 0.3.5). The main visible changes are supply-chain pinning of the workflow's own actions and a mention prompt that now defers its handling rules to a bundled skill.
actions/checkoutandastral-sh/setup-uvare now referenced by commit SHA (with the version as a comment), and the uv download is verified against a checksum, so a moved tag can no longer change what these workflows run (Pin third-party actions, uv, and pre-commit hooks to commits and checksums max-sixty/tend#1463).tend-mentionnow invokes/tend-ci-runner:mentionand passes only the event description; the per-event instructions ("read the full context", "exit silently if…") that were inlined in the YAML now live in that skill.claude@0.3.6action): CI polls no longer wait on jobs held for environment approval (Stop the CI poll from waiting on a job held for environment approval max-sixty/tend#1473) — relevant here for theHosted PR previewjobs therunning-tendoverlay currently skips by hand; nightly reads the last successful run more robustly so a cached listing can't widen its review range (fix(nightly): read the last successful run at several limits so a cached listing can't widen the review range max-sixty/tend#1468); triage opens a PR when a maintainer is reasonably likely to merge it (fix(triage): open a PR when a maintainer is reasonably likely to merge it max-sixty/tend#1471); and bot repairs resume from live PR state (Resume unfinished bot repairs from live PR state max-sixty/tend#1479).Codex-only changes in this release (new default Codex model, credential handoff) don't affect this repo, which runs the Claude harness with no model pin.
Full upstream diff: 0.3.5...0.3.6