ci(pilot): coworkerz-ci Pin auf 511ae1b (zizmor-Fix-Validierung) - #34
Merged
Merged
Conversation
Validiert als Pilot-Caller den template-injection-Fix der Reusables (coworkerz-ci PR#1, self-zizmor gruen): Befehls-Inputs via eval, Multi-Target ruff "src tests benchmarks" via unquoted env-Expansion. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
zizmor kann mit repo-scoped GITHUB_TOKEN keine Tags/Commits des privaten coworkerz-ci lesen -> Audit seit 06-04 faelschlich rot. SHA-Echtheit wird stattdessen bei jedem Bump via gh api Pre/Post verifiziert (Backup-First- Konvention). Begruendung als Kommentar an der Pin-Zeile. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Inline-Ignore wirkt nicht (Audit crasht hart statt Finding zu liefern, "fatal: no audit was performed"). Kanonische Loesung per zizmor-Docs: online-audits: false. Trade-off im Workflow dokumentiert; SHA-Echtheit des coworkerz-ci-Pins wird bei jedem Bump via gh api verifiziert. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
marcohost33-maker
marked this pull request as ready for review
June 6, 2026 07:49
marcohost33-maker
added a commit
that referenced
this pull request
Jun 7, 2026
…6 + D14) (#42) MINOR bump per SemVer (gap= forwarding, TransientGridWarning, SOURCE_DATE_EPOCH are backward-compatible additions). CITATION.cff was still at 0.2.0 (stale since 04-17) -> 0.4.0/2026-06-07. Board note "v0.3.0-Release-Tag" was stale: v0.3.0 tag exists since 05-28. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
online-audits: false; Trade-off im Workflow dokumentiert, SHA-Echtheit wird bei jedem Bump via gh api verifiziert.CHANGELOG: n/a (reine CI-Infrastruktur, kein Code/Methodik-Touch).
Test plan