chore(security): regenerate the approved publish-workflow revisions - #3701
Conversation
66a6fa2 to
21c1b6f
Compare
@coderabbitai full review |
|
✅ Action performedFull review finished. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Organization UI (inherited) Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details🧰 Additional context used🧠 Learnings (1)📚 Learning: 2026-07-03T03:44:11.507ZApplied to files:
🔇 Additional comments (1)
📝 WalkthroughWalkthroughThe Merge Risk: 🟡 Moderate · up to The GitHub Config OCI verifier now accepts artifacts from two pinned workflow revisions. Future valid artifacts could be rejected by Flux if this exact pinning contract is not intentional, so the contract should be confirmed before merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Refresh the approved publish revisions and their consumer matchers from
the deployed artifacts and current publish-workflow pins. Every consumer
resolved on both halves, and each matcher accepts exactly its approved pair.
Part of #3308.