Skip to content

ci: pin workflow actions for foundation gates - #317

Draft
KooshaPari wants to merge 42 commits into
mainfrom
codex/byteport-workflow-pins
Draft

ci: pin workflow actions for foundation gates#317
KooshaPari wants to merge 42 commits into
mainfrom
codex/byteport-workflow-pins

Conversation

@KooshaPari

Copy link
Copy Markdown
Owner

Summary

Stacked workflow-only repair for BytePort PR #313, based on its current foundation head.

  • Replace the corrupted setup-go SHA with the verified v6 SHA already used by the repository.
  • Pin Tier-0 setup-node and golangci action references so governance integrity can evaluate them.
  • Preserve application/dependency scope; this branch only changes workflow pins.

Validation

  • YAML/workflow syntax and governance pin checks passed locally.
  • git diff --check passed.

This is a draft pending CI rerun and review of the parent PR remaining Rust/frontend/audit gates.

KooshaPari and others added 30 commits July 14, 2026 15:09
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@github-actions

Copy link
Copy Markdown

Legacy Tooling Scan Report

Severity Count
Critical 0
High 0
Medium 0
Low 0

No violations detected.

This is a WARN-mode scan. Fix before strict enforcement begins.

@github-actions

Copy link
Copy Markdown

Legacy Tooling Scan Report

Severity Count
Critical 0
High 0
Medium 0
Low 0

No violations detected.

This is a WARN-mode scan. Fix before strict enforcement begins.

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant