engineering: one cicd revision, vendored and called alike - #16
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This repository consumed nicodes/cicd twice and the two disagreed: the helpers under scripts/engineering came from one revision, and the reusable workflows called with @<sha> came from another. Neither half is wrong on its own, which is why it went unnoticed -- "which revision of cicd is this product on" had no answer. Both now name nicodes/cicd v0.2.1, and pins.mjs refuses a product where they differ, so they can only move together from here. The workflow pins carry the version in a trailing comment. The pin is still the commit -- a tag can be deleted and recreated, and SOURCE.json records a commit so a tag there could not be compared with it at all -- and the comment is what makes the SHA legible in review. v0.2.1 is also the first cicd release with its own helper checkouts pinned consistently. Those reusable workflows check cicd out again for helpers/, and GitHub resolves only the caller's ref; until now a product that pinned backup.yml by SHA still ran helpers from whatever commit was written inside it, 24 to 34 commits behind, at two different revisions. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
nicodes
force-pushed
the
chore/cicd-v0.2.0
branch
from
September 29, 2026 12:32
a70a6bc to
3044359
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This repository consumed
nicodes/cicdtwice, and the two disagreed:scripts/engineering(SOURCE.json.revision)@<sha>Neither half is wrong on its own, which is why it went unnoticed — "which revision of cicd is this product on" had no answer. Across the portfolio, products ran helper code from one revision while their backup and vulnerability workflows came from another; one pinned three at once.
Both halves now name cicd v0.2.0, and
helpers/pins.mjsrefuses a product where they differ (nicodes/cicd#64), so they can only move together from here.Why the pin is still a commit
The workflow pins carry the version in a trailing comment, but the pin itself stays the 40-hex commit. A tag can be deleted and recreated;
SOURCE.jsonrecords a commit, so a tag there could not be compared with it at all. The comment is what makes the SHA legible in review.What v0.2.0 is
cicd's second release, and the first releases that repository has ever had. Its reusable workflows check cicd out again for
helpers/, and GitHub resolves only the caller's ref — so until now a product that carefully pinnedbackup.ymlby SHA still ran helpers from whatever commit was written inside it: 24 to 34 commits behind, at two different revisions. Cutting a release repins those mechanically, replacing the manual bump-along rule that had already failed once in production.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.