fix(ci): restore reachable standards workflow pins - #87
Conversation
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (4)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (28)
🧰 Additional context used📓 Path-based instructions (1)Never create these in the repo root:📄 CodeRabbit inference engine (.github/copilot-instructions.md) Files:
🪛 zizmor (1.29.0).github/workflows/mirror.yml[warning] 16-16: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow (secrets-inherit) 🔇 Additional comments (4)
📝 SummarySummary by CodeRabbit
WalkthroughFour GitHub Actions workflows now pin their reusable ChangesReusable workflow pin updates
Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk:⚪ Minimal · up to This restores the reusable workflow references for governance, Hypatia scanning, mirroring, and scorecard checks while retaining SHA pinning. No current merge-blocking risk is identified. Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |



Replace the unreachable standards reusable-workflow commit 7fdc2705df74b4e352d2a1cde3e87a5923fdf329 with reachable standards main commit 092dedada188f56c5915f74a5fd40aac093742c3. The old SHA is an intermediate commit from squash-merged standards PR #596: it exists, but GitHub rejects it for cross-repository reusable workflows before creating jobs. This restores Hypatia/SARIF and the other affected workflows without weakening SHA pinning or branch protection. Estate incident: 251 active workflow files across 70 repositories in hyperpolymath and metadatastician.