Pulse/.github
pulse-triage[bot] 0168dd3be8 fix(ci): freeze reviewed action pins from Dependabot version updates
action_consumer_manifests.json pins each release-consumed action to an exact SHA plus the upstream action.yml sha256, and release_promotion_policy_test.py requires every workflow step to match. Dependabot's github-actions group bumps those SHAs, so every group proposal fails the manifest contract and cannot be repaired offline. Ignore the eight governed actions for version updates and guard the policy against the manifest so pin refreshes stay explicit reviewed work. This resolves the recurring failing actions-minor-patch proposal (#2139).

Change-source: pulse-maintainer
2026-09-23 08:04:21 +01:00
..
codeql/extensions/pulse-security-models Harden remaining CodeQL security boundaries 2026-07-09 19:46:40 +01:00
ISSUE_TEMPLATE Preserve secondary issue feedback 2026-08-29 12:24:03 +01:00
scripts fix(triage): preserve concurrent community label changes 2026-09-08 12:00:46 +01:00
workflows fix(release): verify the private Pro source pair before creating a draft 2026-09-20 14:24:41 +01:00
dependabot.yml fix(ci): freeze reviewed action pins from Dependabot version updates 2026-09-23 08:04:21 +01:00
FUNDING.yml chore: add Ko-fi to funding options 2025-12-25 20:23:00 +00:00
PULL_REQUEST_TEMPLATE.md Port issue-first contribution policy to v6 docs 2026-05-01 20:28:11 +01:00
v6_rc_feedback_hub.md Rename user-facing RC wording to prerelease 2026-03-25 10:35:00 +00:00