Skip to content

chore(tooling): migrate to vergil v2.1#155

Merged
wphillipmoore merged 3 commits into
developfrom
feature/154-vergil-v2-1
Jun 23, 2026
Merged

chore(tooling): migrate to vergil v2.1#155
wphillipmoore merged 3 commits into
developfrom
feature/154-vergil-v2-1

Conversation

@wphillipmoore

Copy link
Copy Markdown
Collaborator

Pull Request

Summary

  • Bump this repo from vergil v2.0 to v2.1 across vergil.toml, CI/CD workflow refs, and the Claude marketplace pin, and grant the ci-security caller actions: read.

Issue Linkage

Notes

  • Scope: vergil.toml v2.0->v2.1; 5 ci.yml refs and 2 cd.yml refs bumped @v2.0->@v2.1; settings.json gained extraKnownMarketplaces.vergil-marketplace.source.ref=v2.1 (key was absent before). actions:read rationale: v2.1 ci-security.yml requests actions:read from callers (vergil-actions#693/#698), added to both top-level and security-job permissions to avoid 'allowed actions:none' startup failure. Version-divergence: vrg-version shows 1.2.4 (unreleased), latest release tag v1.2.3; VERSION not edited per instructions.

…05/54906

concurrent-ruby 1.3.6 carries three HIGH-severity advisories (AtomicReference#update livelock, ReentrantReadWriteLock write-lock overflow, ReadWriteLock wrong-thread release), all fixed in 1.3.7. Clears the security/trivy and audit/dependencies CI failures. Conservative lockfile-only update of a transitive dependency; no Gemfile change.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@wphillipmoore wphillipmoore merged commit 5ce1793 into develop Jun 23, 2026
24 checks passed
@wphillipmoore wphillipmoore deleted the feature/154-vergil-v2-1 branch June 23, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant