diff --git a/.github/workflows/README.md b/.github/workflows/README.md index 584f6f6..c5cd681 100644 --- a/.github/workflows/README.md +++ b/.github/workflows/README.md @@ -7,8 +7,8 @@ against a pinned submodule revision. Reusable workflows are sourced from [`NDDev-it-com/ci-workflows`](https://github.com/NDDev-it-com/ci-workflows) -release `0.10.0`, pinned to commit -`eb7bd953dc9741e559cb9e357c2d36c9b4de5a88`. +release `0.12.0`, pinned to commit +`2ccb80e96f5771b6a6b4eae63a4f47e232906dc7`. ## Workflows diff --git a/.github/workflows/actionlint.yml b/.github/workflows/actionlint.yml index acc6fc3..b6518cd 100644 --- a/.github/workflows/actionlint.yml +++ b/.github/workflows/actionlint.yml @@ -19,4 +19,4 @@ jobs: name: actionlint permissions: contents: read - uses: NDDev-it-com/ci-workflows/.github/workflows/actionlint.yml@eb7bd953dc9741e559cb9e357c2d36c9b4de5a88 # 0.10.0 + uses: NDDev-it-com/ci-workflows/.github/workflows/actionlint.yml@2ccb80e96f5771b6a6b4eae63a4f47e232906dc7 # 0.12.0 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ac73780..d9be9ff 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -21,7 +21,7 @@ jobs: contents: read security-events: write # Publish CodeQL analysis to code scanning. actions: read # Read workflow metadata for the actions language. - uses: NDDev-it-com/ci-workflows/.github/workflows/public-codeql.yml@eb7bd953dc9741e559cb9e357c2d36c9b4de5a88 # 0.10.0 + uses: NDDev-it-com/ci-workflows/.github/workflows/public-codeql.yml@2ccb80e96f5771b6a6b4eae63a4f47e232906dc7 # 0.12.0 with: languages: '["actions"]' queries: security-and-quality diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 1585e1c..b7f84c9 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -16,4 +16,4 @@ jobs: permissions: contents: read pull-requests: write # Comment when dependency policy rejects a change. - uses: NDDev-it-com/ci-workflows/.github/workflows/public-dependency-review.yml@eb7bd953dc9741e559cb9e357c2d36c9b4de5a88 # 0.10.0 + uses: NDDev-it-com/ci-workflows/.github/workflows/public-dependency-review.yml@2ccb80e96f5771b6a6b4eae63a4f47e232906dc7 # 0.12.0 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4e88ac5..57c0600 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -290,7 +290,7 @@ jobs: id-token: write # Exchange workflow identity for attestations. attestations: write # Publish provenance and SBOM attestations. artifact-metadata: write # Record the actions/attest artifact storage entry (required at v4.1.1). - uses: NDDev-it-com/ci-workflows/.github/workflows/release-supply-chain.yml@eb7bd953dc9741e559cb9e357c2d36c9b4de5a88 # 0.10.0 + uses: NDDev-it-com/ci-workflows/.github/workflows/release-supply-chain.yml@2ccb80e96f5771b6a6b4eae63a4f47e232906dc7 # 0.12.0 with: version: ${{ github.ref_name }} package_name: nddev-zcode-app diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index fd14a63..c0aea9f 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -19,4 +19,4 @@ jobs: contents: read actions: read # Inspect workflow metadata for Scorecard checks. id-token: write # Obtain OIDC identity for the Scorecard artifact. - uses: NDDev-it-com/ci-workflows/.github/workflows/public-scorecard-json.yml@eb7bd953dc9741e559cb9e357c2d36c9b4de5a88 # 0.10.0 + uses: NDDev-it-com/ci-workflows/.github/workflows/public-scorecard-json.yml@2ccb80e96f5771b6a6b4eae63a4f47e232906dc7 # 0.12.0 diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index d81e0d7..1bdf3ab 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -16,4 +16,4 @@ concurrency: jobs: secret-scan: name: Secret scan - uses: NDDev-it-com/ci-workflows/.github/workflows/secret-scan.yml@eb7bd953dc9741e559cb9e357c2d36c9b4de5a88 # 0.10.0 + uses: NDDev-it-com/ci-workflows/.github/workflows/secret-scan.yml@2ccb80e96f5771b6a6b4eae63a4f47e232906dc7 # 0.12.0 diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 0e94950..4cf1311 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -21,7 +21,7 @@ jobs: permissions: contents: read security-events: write # Publish workflow-analysis results to code scanning. - uses: NDDev-it-com/ci-workflows/.github/workflows/zizmor-sarif.yml@eb7bd953dc9741e559cb9e357c2d36c9b4de5a88 # 0.10.0 + uses: NDDev-it-com/ci-workflows/.github/workflows/zizmor-sarif.yml@2ccb80e96f5771b6a6b4eae63a4f47e232906dc7 # 0.12.0 with: persona: pedantic min_severity: low diff --git a/build/release-evidence.json b/build/release-evidence.json index be31f37..10bb61f 100644 --- a/build/release-evidence.json +++ b/build/release-evidence.json @@ -2,11 +2,11 @@ "schema_version": 2, "module": { "repository": "NDDev-it-com/nddev-zcode-app", - "setup_digest": "sha256:c0b1a5e3f2bc2e4aaf54caa3edf96a42f064f9e1057d764a950c149de043412b" + "setup_digest": "sha256:c4f37c75b84415ce542bbddb5765a519f44e58d5ed00a075c967c2bb2c19d85b" }, "harness": { "repository": "NDDev-it-com/nddev-harnesses", - "commit": "7083e7e6764d4beaf6096ba19b28ded32f00ffd1" + "commit": "1980bef79cf1fe04c7ca6dbf51f8aa42c004d6be" }, "adapter": { "id": "zcode", @@ -30,8 +30,8 @@ } ], "lanes": [], - "generated_at_utc": "2026-07-21T08:53:03Z", - "expires_at_utc": "2027-01-17T08:53:03Z", + "generated_at_utc": "2026-07-22T02:29:14Z", + "expires_at_utc": "2027-01-18T02:29:14Z", "promotion": { "decision": "pending", "waivers": []