Skip to content

chore(ci): bump signetry-reviewer pin to v0.2.0 - #101

Merged
bkd-dotcom merged 1 commit into
mainfrom
chore/bump-reviewer-pin
Aug 18, 2026
Merged

chore(ci): bump signetry-reviewer pin to v0.2.0#101
bkd-dotcom merged 1 commit into
mainfrom
chore/bump-reviewer-pin

Conversation

@bkd-dotcom

Copy link
Copy Markdown
Member

Core still pinned signetry-reviewer@v0.1.2, so the reviewer fixes merged today were inert here.

v0.2.0 brings:

  • the fix for CI rules firing on YAML comments — this repo's own fix(ci): advisory reviewer could never comment on a fork PR (403) #92 was returned a 🔴 Block verdict for two comment lines explaining why it deliberately avoids pull_request_target, which is exactly how that bug was found
  • ci.pull_request_target now matching the real trigger in all four YAML forms
  • the new supply.dependency_skew check (lockfile changed without its manifest) — advisory and MEDIUM, so it withholds auto-merge without rejecting Dependabot refreshes
  • deser.introduced (insecure deserialization in a diff), also advisory

actionlint clean. The same bump is included in the 9 rollout PRs for the other repos.

Picks up the fix for CI rules firing on YAML comments — this repo's own
#92 was returned a Block verdict for two comment lines explaining why it
deliberately avoids pull_request_target, which is what surfaced that bug.

Also brings in the new supply.dependency_skew check (lockfile changed
without its manifest), advisory and MEDIUM so it withholds auto-merge
without rejecting Dependabot refreshes.
@github-actions

Copy link
Copy Markdown

Signetry Reviewer — 🟣 Escalate to a designated reviewer

Escalate to a designated reviewer — this PR touches security-sensitive surface (.github/workflows/reviewer.yml). No blocking issue was found automatically, but a human owner should sign off.

Deterministic gates (the authority)

Gate Status
Required status check ⏳ pending
Secret scan ✅ clean
CI permission / OIDC ✅ no forbidden change
Dependency skew ✅ ok
All green

Findings (1, 0 blocking)

  • 🟡 Change touches a protected path: .github/workflows/reviewer.yml .github/workflows/reviewer.yml (via cross-check)
    • .github/workflows/reviewer.yml matches a protected pattern (.github/workflows/*). Changes here alter shared/foundational surface and warrant a designated reviewer.
    • Fix: Route to a code owner / architecture reviewer.

Sensitive surface

This PR changes security-sensitive paths that warrant a designated reviewer:

  • .github/workflows/reviewer.yml

Merge

A designated reviewer / code owner should sign off before merge (sensitive surface).

This review is advisory. It never merges on its own judgement — the deterministic gates + a human are the authority. Findings can have false negatives; a green bot verdict is not a guarantee.

@bkd-dotcom
bkd-dotcom merged commit 6b2e262 into main Aug 18, 2026
8 checks passed
@bkd-dotcom
bkd-dotcom deleted the chore/bump-reviewer-pin branch August 18, 2026 20:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant