fix(repo-policy-sync): recognize tagged newer SHA pins - #44
Merged
AlexanderLanin merged 1 commit intoSep 15, 2026
Conversation
AlexanderLanin
requested review from
MaximilianSoerenPollak,
dcalavrezo-qorix and
nradakovic
as code owners
September 15, 2026 15:03
AlexanderLanin
force-pushed
the
fix-repo-policy-sync-tagged-sha-comparison
branch
from
September 15, 2026 15:08
c25a21c to
f02e5ff
Compare
AlexanderLanin
force-pushed
the
fix-repo-policy-sync-tagged-sha-comparison
branch
from
September 15, 2026 15:10
f02e5ff to
b335f43
Compare
MaximilianSoerenPollak
approved these changes
Sep 15, 2026
MaximilianSoerenPollak
left a comment
Contributor
There was a problem hiding this comment.
Such a unique / niche issue.
But I think this can happen so we better catch it before.
Member
Author
|
its not unique unfortunately, v6 and v7 always diverse with the first patch applied to v6 after v7 release |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This fixes repository policy evaluation failures for full commit-SHA pins when the configured minimum release and current release use diverged Git histories. Without this, a newer tagged SHA such as actions/checkout v7 is rejected against minimum v6, causing false policy failures across repositories.
The GitHub-reference minimum-version operation now resolves semantic versions for known tags matching a full SHA before falling back to ancestry comparison. Tagged SHAs at or above the minimum remain unchanged; tagged older SHAs move to the minimum tag. Untagged diverged SHAs retain the existing safety failure behavior. Regression coverage documents the newer tagged SHA case.