fix: pin agent-shield reusable workflow to SHA#132
Conversation
|
Warning Review limit reached
More reviews will be available in 31 minutes and 55 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more credits in the billing tab to continue. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (4)
📝 WalkthroughWalkthroughBoth workflow files update their reusable workflow references from a floating version tag ( ChangesWorkflow Reference Pinning
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related issues
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Pins the repository’s AgentShield caller workflow to a specific commit SHA to comply with the org’s GitHub Actions pinning policy and resolve the reported compliance finding.
Changes:
- Replaces the reusable workflow reference from
@v1to a full commit SHA. - Adds a
# v1inline comment for human-readable version context.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Outdated review (superseded by re-review at
|
|
@claude[agent] - Address the open comments. Ensure the standard is also updated with the SHA pinning as part of this PR. |
9a26863 to
fee3ae1
Compare
Updated standards/workflows/agent-shield.yml to pin the reusable workflow to the same SHA (@208ec2d69b75227d375edf8745d84fbac05a76b2) with the Commit: fee3ae1 |
Outdated review (superseded by re-review at
|
|
Auto-rebase failed — merge conflict — this branch has conflicts with Please resolve the conflicts and push: |
donpetry-bot
left a comment
There was a problem hiding this comment.
Reviewed by the don-petry PR-review cascade (triage: haiku 4.5 → deep: sonnet 4.6 + duck: gpt-5.4 → audit: opus 4.6). Reply with @don-petry if you need a human.
|
@claude Please address all open review comments on this PR from CodeRabbit and Copilot. |
|
Claude finished @don-petry's task in 1m 12s —— View job Review comments addressed
All open CodeRabbit and Copilot comments have already been resolved: Copilot — uses: petry-projects/.github/.github/workflows/agent-shield-reusable.yml@208ec2d69b75227d375edf8745d84fbac05a76b2 # v1CodeRabbit — Latest review (2026-05-04): Approved with no actionable comments. Nothing to address. The PR diff confirms both files are updated symmetrically —
|
|
@claude There is an unresolved Copilot review comment on this PR (created 2026-04-14, before the comment-trigger was added to
Please:
Generated by Claude Code |
|
Claude finished @don-petry's task in 51s —— View job Copilot review comment — already resolved
Both files are already identical and correctly pinned:
uses: petry-projects/.github/.github/workflows/agent-shield-reusable.yml@208ec2d69b75227d375edf8745d84fbac05a76b2 # v1No other files in the repository reference The Copilot review thread can be marked as resolved — the fix was committed in |
Pull request was closed
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
26 similar comments
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
|
@donpetry-bot I'm on it — starting a fresh review now. Results will appear in a few minutes. |
Summary
uses: petry-projects/.github/.github/workflows/agent-shield-reusable.yml@v1to its commit SHA (208ec2d69b75227d375edf8745d84fbac05a76b2)# v1comment for human readability per the org action-pinning policyCompliance
Resolves the compliance finding from the weekly audit:
unpinned-actions-agent-shield.yml.Standard: standards/ci-standards.md#action-pinning-policy
SHA was looked up via:
Closes #104
Generated with Claude Code
Summary by CodeRabbit