Repository navigation
CI & reusable workflows: bump Actions to current majors (checkout v7, setup-uv v10, upload v7, download v8) - #343
Conversation
… setup-uv v10, upload v7, download v8) Mechanical version bump across the workflows. The two artifact-download shapes are unchanged in behaviour: single-name downloads extract flat into runner.temp (the post jobs read runner.temp/findings.json), and the summarizer's pattern download reads **/findings.json recursively, so a per-artifact subdirectory is fine either way. node24 is on the hosted runners. Verified by a canary review after merge, revert-ready. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
Round 1 — reviewed head b5a723e4 — reviewer summarizer:hermes/gpt-5.6-terra over coverage+credentials+deployment+general+lifecycle+prose.
terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.
Verdict: 2 blocking, 0 advisory.
2 findings attached to the lines below.
Blocking verdict: replace astral-sh/setup-uv@v10 in CI and the advisory workflow with an existing, resolvable release ref. The CI occurrence is corroborated by coverage, deployment, lifecycle, and prose; credentials independently identifies the advisory-workflow occurrence. Rejected: coverages statement that upstream tags exist only through v7 is contradicted by the more specific v10.0.0/v10.0.1 evidence; its core non-resolving-v10 finding was retained. The deployment, lifecycle, and prose CI reports were merged as duplicates of the same action reference rather than recorded separately. General reported no findings.
…ajor exists) astral-sh/setup-uv publishes exact releases up to v10.0.1 but only moving major tags through v7, so @v10 does not resolve. Pin the exact v10.0.1; checkout@v7, upload-artifact@v7 and download-artifact@v8 keep their moving majors, which do exist. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
# Conflicts: # CHANGELOG.md
Digest #332, the mechanical part. Bumps the four pinned actions to their current majors across every workflow.
The one behaviour to watch is download-artifact (v4 → v8). It is safe here: the post jobs download a single named artifact into
runner.temp, which stays flat, sorunner.temp/findings.jsonstill resolves; the summarizer's pattern download reads**/findings.jsonrecursively, so a per-artifact subdirectory is fine. node24 (required by checkout v5+) is on the hosted runners.Because these reusable workflows run from
@main, a break only shows after merge — so this merges then gets a canary review on a throwaway PR immediately, and I revert if the review does not post. Held for a watched window on purpose.🤖 Generated with Claude Code