Commit graph

31 commits

Author SHA1 Message Date
pulse-triage[bot]
be6179c2d2 build(ci): refresh reviewed GitHub Actions pins
Dependabot #2094, #2095 and #2096 bump actions/setup-go 6.4.0 -> 7.0.0, signpath/github-action-submit-signing-request 2 -> 3.0 and actions/github-script 8.0.0 -> 9.0.0. Each proposal is blocked only by the reviewed pin constants, the workflow-trust allowlist, the release-consumer action manifest and the installer governance assertions that hard-code the previous revisions. Carry all three bumps with those artifacts in one commit so the proposals can be closed as superseded.

All three actions keep the node24 runtime and their existing inputs and outputs; no consumer interface, installer behaviour or public contract changes. The deployment-installability and agent-lifecycle workflow references are pin-only.

Contract-Neutral: Reviewed action pin refresh with identical node24 consumer interfaces and unchanged inputs/outputs; no public-contract or installer-behaviour delta.
Change-source: pulse-maintainer
2026-09-20 08:16:44 +01:00
pulse-triage[bot]
5add9bfc36 fix(ci): permit audited caller-only permission inheritance
The stable-install smoke body is intentionally workflow_call-only so its read-only continuity caller and draft-capable release caller can supply different explicit token budgets. Treat that exact no-override shape as an auditable permission boundary while continuing to reject independent triggers and job permission overrides.

Validation: 41 workflow-trust tests, repository workflow audit, focused install-smoke contract tests, Python compilation and diff checks pass.

Change-source: pulse-maintainer
2026-09-05 09:06:17 +01:00
pulse-triage[bot]
6d8546b756 Keep Actions workflows on Node 24
Replace the remaining Node 20 action pins before GitHub removes that runtime, and make the reviewed Node 24 pins a workflow trust invariant.

Change-source: pulse-maintainer
2026-09-04 11:08:34 +01:00
pulse-triage[bot]
0b72eca737 Keep privileged jobs on ephemeral hosted runners
Retire the unused self-hosted live qualification workflow and reject future secret- or write-capable jobs on persistent or dynamically selected runners. Keep live Patrol qualification as a disposable lab operation.

Change-source: pulse-maintainer
2026-09-04 09:30:11 +01:00
pulse-triage[bot]
457aa90458 Keep release workflows free of implicit trust inputs
Remove the pull-request secret exception, drop inert E2E secret references, and disable setup-node caches at release trust boundaries. Document the exact metadata-only privileged trigger exception.

Change-source: pulse-maintainer
2026-09-04 07:30:35 +01:00
pulse-triage[bot]
6575ebd928 Tighten the privileged close hook boundary
Reject job-level permission expansion and unsafe checkout selection in the closed-PR capacity workflow, and report cancellation requests separately from runs that completed during the API race.

Change-source: pulse-maintainer
2026-09-02 11:05:04 +01:00
pulse-triage[bot]
af0e8f8d39 Reclaim CI capacity when pull requests close
Cancel queued and running validation workflows for a closed pull request head so obsolete matrices cannot hold the hosted-runner limit and delay required checks. Keep the privileged close hook bound to reviewed default-branch code and cover reopen, branch-reuse, identity, and API-race boundaries.

Change-source: pulse-maintainer
2026-09-02 11:03:53 +01:00
pulse-triage[bot]
5b204cdc75 Close mirrored workflow scalar syntax gaps
Recognize bare sequence entries and every valid block scalar header across executable action inputs, run scripts, and step environment boundaries.

Change-source: pulse-maintainer
2026-09-01 22:13:37 +01:00
pulse-triage[bot]
22cc59cc2c Reject template injection in executable action inputs
Change-source: pulse-maintainer
2026-09-01 21:35:35 +01:00
pulse-triage[bot]
a869475bf1 Reject flow-nested YAML trust aliases
Change-source: pulse-maintainer
2026-09-01 21:21:45 +01:00
pulse-triage[bot]
8cd5c2cae5 Reject hidden workflow trust structure
Change-source: pulse-maintainer
2026-09-01 21:18:26 +01:00
pulse-triage[bot]
028ccbd35f Keep OIDC attestations on hosted runners
Change-source: pulse-maintainer
2026-09-01 20:17:13 +01:00
pulse-triage[bot]
c10e93943b Parse workflow job trust boundaries structurally
Change-source: pulse-maintainer
2026-09-01 19:46:57 +01:00
pulse-triage[bot]
5c26a8f6d1 Close privileged workflow cache audit bypasses
Change-source: pulse-maintainer
2026-09-01 19:31:06 +01:00
pulse-triage[bot]
f61815839f Keep unsigned caches out of privileged workflows
Change-source: pulse-maintainer
2026-09-01 19:29:37 +01:00
pulse-triage[bot]
de41ea1883 Preserve workflow taint across branches
Change-source: pulse-maintainer
2026-09-01 17:34:30 +01:00
pulse-triage[bot]
7fd93457f1 Harden workflow alias taint tracking
Change-source: pulse-maintainer
2026-09-01 16:58:55 +01:00
pulse-triage[bot]
4f7a3d0006 Close runner output alias bypasses
Change-source: pulse-maintainer
2026-09-01 16:54:07 +01:00
pulse-triage[bot]
c55db584c1 Harden GitHub command file data boundaries
Change-source: pulse-maintainer
2026-09-01 16:32:15 +01:00
pulse-triage[bot]
97a39e8819 Block dispatch payload shell injection
Change-source: pulse-maintainer
2026-09-01 14:35:07 +01:00
pulse-triage[bot]
faf69f76e6 Keep workflow outputs out of generated shell
Change-source: pulse-maintainer
2026-09-01 10:16:41 +01:00
pulse-triage[bot]
ba727edf12 Refresh trusted checkout action
Change-source: pulse-maintainer
2026-09-01 02:31:08 +01:00
pulse-triage[bot]
0f7a8683c2 Block privileged workflow code ingress
Change-source: pulse-maintainer
2026-08-31 18:21:45 +01:00
pulse-triage[bot]
8f877bee14 Bind privileged workflow runs to canonical code
Change-source: pulse-maintainer
2026-08-31 17:09:53 +01:00
pulse-triage[bot]
69cbe5f3b8 Enforce protected GitHub checkout baseline 2026-08-31 13:21:25 +01:00
pulse-triage[bot]
fda955627f Bound GitHub Actions job runtimes 2026-08-31 02:00:09 +01:00
pulse-triage[bot]
47c1cee895 Enforce least-privilege job tokens 2026-08-30 22:11:40 +01:00
pulse-triage[bot]
a0dfdadc5e Close workflow trust policy gaps 2026-08-30 15:06:00 +01:00
pulse-triage[bot]
21007a8662 Isolate private governance from pull requests 2026-08-30 15:02:41 +01:00
pulse-triage[bot]
d8986c139a Enforce workflow data trust boundaries
Contract-Neutral: Moves workflow expressions into environment data flow without changing deployment interfaces or behavior.
2026-08-30 04:56:34 +01:00
pulse-triage[bot]
a2bfadba7b Enforce workflow execution trust boundaries 2026-08-30 04:44:25 +01:00