Skip to content

chore(ci): bump standards reusable workflow pins#52

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/bump-standards-pins-2026-06-24
Jun 24, 2026
Merged

chore(ci): bump standards reusable workflow pins#52
hyperpolymath merged 1 commit into
mainfrom
chore/bump-standards-pins-2026-06-24

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Bumps stale hyperpolymath/standards/.github/workflows/*-reusable.yml pins to current standards HEAD (d135b05bfc647d0c0fbfedc7e80f37ea50f49236) to clear governance 'Check Workflow Staleness' (ADR-003) failures. CI-pin changes only.

OWNER-AUTHORIZED estate pin-bump campaign 2026-06-24.

🤖 Generated with Claude Code

Bump stale hyperpolymath/standards reusable workflow pins to current
standards HEAD (d135b05bfc647d0c0fbfedc7e80f37ea50f49236) to clear governance 'Check Workflow
Staleness' (ADR-003) failures.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit a96251c into main Jun 24, 2026
1 check passed
@hyperpolymath
hyperpolymath deleted the chore/bump-standards-pins-2026-06-24 branch June 24, 2026 14:37
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml d135b05bfc647d0c0fbfedc7e80f37ea50f49236 🟢 7.3
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 0/27 approved changesets -- score normalized to 0
Dependency-Update-Tool🟢 10update tool detected
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions🟢 8detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 7binaries present in source code
Signed-Releases⚠️ -1no releases found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
License🟢 10license file detected
SAST🟢 9SAST tool detected but not run on all commits
Fuzzing🟢 10project is fuzzed
Branch-Protection🟢 4branch protection is not maximal on development and all release branches
Vulnerabilities🟢 46 existing vulnerabilities detected
Contributors🟢 6project has 2 contributing companies or organizations -- score normalized to 6
CI-Tests🟢 1027 out of 27 merged PRs checked by a CI test -- score normalized to 10

Scanned Files

  • .github/workflows/secret-scanner.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant