diff --git a/.github/workflows/w3-lab-auto-provision.yml b/.github/workflows/w3-lab-auto-provision.yml index 009ccc34..2fdb65c5 100644 --- a/.github/workflows/w3-lab-auto-provision.yml +++ b/.github/workflows/w3-lab-auto-provision.yml @@ -56,7 +56,7 @@ concurrency: jobs: gate: name: Pre-run cost check - uses: vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@refs/heads/main # oidc-trust + uses: vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@main # oidc-trust permissions: contents: read id-token: write diff --git a/docs/programs/release-engineering/dossiers/optics-public.json b/docs/programs/release-engineering/dossiers/optics-public.json index 5bdc5757..47ee68e2 100644 --- a/docs/programs/release-engineering/dossiers/optics-public.json +++ b/docs/programs/release-engineering/dossiers/optics-public.json @@ -60,9 +60,9 @@ { "accepted_as_pin": false, "kind": "unpinned", - "name": ".github/workflows/w3-lab-auto-provision.yml vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@refs/heads/main # oidc-trust", + "name": ".github/workflows/w3-lab-auto-provision.yml vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@main # oidc-trust", "required_for_publish": true, - "value": "vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@refs/heads/main # oidc-trust" + "value": "vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@main # oidc-trust" } ], "private_distribution": { diff --git a/docs/programs/release-engineering/generated/evaluations.json b/docs/programs/release-engineering/generated/evaluations.json index 1703af1c..89fc7c47 100644 --- a/docs/programs/release-engineering/generated/evaluations.json +++ b/docs/programs/release-engineering/generated/evaluations.json @@ -10,7 +10,7 @@ "release_success": false, "requirements": [ { - "detail": "pin python-build-hatchling is unpinned; pin node-toolchain is unpinned; pin cli-tarball is unrecorded; pin .github/workflows/w3-lab-auto-provision.yml vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@refs/heads/main # oidc-trust is unpinned", + "detail": "pin python-build-hatchling is unpinned; pin node-toolchain is unpinned; pin cli-tarball is unrecorded; pin .github/workflows/w3-lab-auto-provision.yml vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@main # oidc-trust is unpinned", "id": "R1", "status": "GAP" }, diff --git a/docs/programs/release-engineering/generated/pin-report.json b/docs/programs/release-engineering/generated/pin-report.json index 69b684a9..d84e1f3a 100644 --- a/docs/programs/release-engineering/generated/pin-report.json +++ b/docs/programs/release-engineering/generated/pin-report.json @@ -220,7 +220,7 @@ "digest_pinned": false, "file": ".github/workflows/w3-lab-auto-provision.yml", "pin_kind": "same_repo_refs_heads_main", - "uses": "vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@refs/heads/main # oidc-trust" + "uses": "vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@main # oidc-trust" }, { "digest_pinned": true, diff --git a/scripts/release/ws11/inventory.mjs b/scripts/release/ws11/inventory.mjs index e82598df..46ab1e08 100644 --- a/scripts/release/ws11/inventory.mjs +++ b/scripts/release/ws11/inventory.mjs @@ -8,11 +8,12 @@ export const REPO_ROOT = join(dirname(fileURLToPath(import.meta.url)), "../../.. const SKIP_DIRS = new Set([".git", "node_modules", "dist", "__pycache__", ".pytest_cache"]); const BINDING_ACTION = /@(?:[0-9a-f]{40}|sha256:[0-9a-f]{64})(?:\s+#\s*\S+)?$/i; const ACTION_USES_LINE = /^\s*(?:-\s+)?uses:\s*(\S+)(?:\s+#\s*(\S+))?\s*$/gm; -// Same-repo reusable workflow at refs/heads/main. The lab billing role trusts -// job_workflow_ref ...@refs/heads/main, so a commit SHA pin would fail AssumeRole. -// This is one exact string, not a general floating-ref allowance. +// Same-repo reusable workflow called at @main. GitHub accepts a branch, tag, +// or commit in uses, and rejects @refs/heads/main with HTTP 422. The OIDC +// job_workflow_ref for that branch is still ...@refs/heads/main. A commit SHA +// would change that claim. This is one exact string, not a general floating-ref allowance. const SAME_REPO_MAIN_WORKFLOW = - "vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@refs/heads/main # oidc-trust"; + "vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@main # oidc-trust"; export function classifyActionUse(uses) { if (BINDING_ACTION.test(uses)) return { digest_pinned: true, pin_kind: "digest" }; diff --git a/scripts/release/ws11/ws11.test.mjs b/scripts/release/ws11/ws11.test.mjs index 22079d29..5b9c7e4d 100644 --- a/scripts/release/ws11/ws11.test.mjs +++ b/scripts/release/ws11/ws11.test.mjs @@ -293,7 +293,7 @@ test("pin report records SHA-pinned workflow and composite actions and the seale assert.deepEqual( approvedMain.map((action) => `${action.file} ${action.uses}`), [ - ".github/workflows/w3-lab-auto-provision.yml vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@refs/heads/main # oidc-trust", + ".github/workflows/w3-lab-auto-provision.yml vantioai/vantio-open-core/.github/workflows/w3-lab-auto-cost-gate.yml@main # oidc-trust", ], ); assert.ok(approvedMain.every((action) => action.digest_pinned === false));