Skip to content

Wire cross-repo reusable-workflow pin propagation (FUTURE-WORK #16) #400

Description

@hyperpolymath

Summary

The standards-side of reusable-pin freshness landed in #397 (ADR-003: the staleness gate tolerates a recency window, and scripts/propagate-workflow-pins.sh performs an audit-first bump). This issue tracks the remaining cross-repo wiring so a deliberate bump fans out automatically.

Remaining work (lives in other repos)

  • hypatia — activate lib/rules/sha_bump_propagation.ex so a "consumer pin is behind standards HEAD" finding is routed (:review), not inert.
  • gitbot-fleet — run propagate-workflow-pins.sh --fix in the flagged consumer and open a draft bump PR (mirror the .git-private-farm dispatch pattern in instant-sync.yml; gate on a PAT, graceful-skip without it).
  • (optional) standards — a scheduled propagate-workflow-pins.yml that audits the fleet and dispatches the above. Sketch only; do not ship cross-repo dispatch without the PAT + owner sign-off (estate "no unattended mutations" guardrail).

Refs

Priority

Low / convenience. The gate no longer forces bumps (consumers are green within the window), so this is a freshness improvement, not a treadmill fix.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesenhancementNew capability or improvement to existing behaviour

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions