mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-10-03 04:38:48 +00:00
action_consumer_manifests.json pins each release-consumed action to an exact SHA plus the upstream action.yml sha256, and release_promotion_policy_test.py requires every workflow step to match. Dependabot's github-actions group bumps those SHAs, so every group proposal fails the manifest contract and cannot be repaired offline. Ignore the eight governed actions for version updates and guard the policy against the manifest so pin refreshes stay explicit reviewed work. This resolves the recurring failing actions-minor-patch proposal (#2139). Change-source: pulse-maintainer |
||
|---|---|---|
| .. | ||
| integration | ||
| run.sh | ||
| test-ci-benchmarks.sh | ||
| test-cloud-public-signup-smoke.sh | ||
| test-common-lib.sh | ||
| test-hot-dev-auth.sh | ||
| test-hot-dev-bg.sh | ||
| test-hot-dev-runtime.sh | ||
| test-install-ps1-parser.sh | ||
| test-install-update-resilience.sh | ||
| test-npm-audit-retry.sh | ||
| test-pulse-auto-update.sh | ||
| test-reclaim-closed-pr-capacity.sh | ||
| test-retired-trial-acquisition-docs.sh | ||
| test-script-reference-integrity.sh | ||
| test-toggle-mock.sh | ||
| test_benchmark_workflow_contract.py | ||
| test_dependabot_config.py | ||
| test_docs_mirror.py | ||
| test_e2e_workflow_contract.py | ||
| test_gitleaks_ignore.py | ||
| test_localized_public_docs.py | ||
| test_npm_audit_retry.py | ||
| test_public_docs_claims.py | ||
| test_release_train_ci_contract.py | ||
| test_repo_docs_link_drift.py | ||
| test_require_safe_gh_attestation.py | ||
| test_root_pair_diagnostic.py | ||
| test_sync_chart_release_metadata.py | ||
| test_telemetry_adoption_report.py | ||
| test_telemetry_schema_parity.py | ||
| test_uuid_layout_diagnostic.py | ||
| test_validate_published_release.py | ||
| test_workflow_trust.py | ||
| test_write_github_output.py | ||