ci: pin dependency-audit reusable workflow to SHA (closes #87)#101
ci: pin dependency-audit reusable workflow to SHA (closes #87)#101
Conversation
Pin petry-projects/.github reusable workflow to commit SHA 208ec2d69b75227d375edf8745d84fbac05a76b2 (v1) to satisfy the action-pinning policy required by ci-standards.md. Closes #87 Co-authored-by: don-petry <don-petry@users.noreply.github.com>
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 44 minutes and 1 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@don-petry — you're the CODEOWNERS owner for this repo. This PR pins the |
|
There was a problem hiding this comment.
Pull request overview
Pins the org-level dependency-audit reusable workflow reference to an immutable commit SHA to comply with the action-pinning policy and resolve the compliance finding in #87.
Changes:
- Updated the reusable workflow reference from the mutable
@v1tag to the full commit SHA (@208ec2d...) with an inline# v1annotation.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Automated review — APPROVEDRisk: LOW SummarySingle-line GitHub Actions workflow change that pins a reusable workflow reference from a mutable @v1 tag to an immutable commit SHA, improving supply chain security and satisfying the org action-pinning policy (issue #87). All CI checks pass (CodeQL, SonarCloud, AgentShield) with zero new issues or security hotspots. Triage escalated due to an internal triage failure, not actual content risk. FindingsInfo
CI statusAll required checks passed (CodeQL, SonarCloud, AgentShield, CI). Backend/Frontend CI correctly skipped — no application code changed. Reviewed by the don-petry PR-review cascade (triage: haiku 4.5 → deep: sonnet 4.6 + duck: gpt-5.4 → audit: opus 4.6). Reply with |



Summary
Pin the
dependency-audit-reusable.ymlreusable workflow reference to its full commit SHA to satisfy the org-level action-pinning policy.Change
SHA
208ec2d69b75227d375edf8745d84fbac05a76b2corresponds to tagv1inpetry-projects/.github, resolved via:Closes #87
Generated with Claude Code