Skip to content

ci: correct the version comment on the pr-size-labeler pin - #797

Merged
thomaspinder merged 3 commits into
mainfrom
ci/pr-size-labeler-version-comment
Sep 30, 2026
Merged

thomaspinder merged 3 commits into
mainfrom
ci/pr-size-labeler-version-comment

Conversation

@thomaspinder

Copy link
Copy Markdown
Collaborator

Motivation

The "Audit workflows" check (zizmor) fails on each pull request opened since 29 September. It reports one finding:

.github/workflows/auto-label.yml:35 [zizmor/ref-version-mismatch] action's hash pin has mismatched or missing version comment: tag points to commit 4e3aa0f77f34

The workflow pins codelytv/pr-size-labeler to commit 095a41f with the comment # v1. The upstream project moved its v1 tag to the v1.11.1 release, so the comment no longer agrees with the pin.

Solution

Change the comment to # v1.10.4. This is the release tag that points to the pinned commit. The pinned commit does not change, so the workflow runs the same code as before.

This PR does not move the pin to v1.11.1. That is a separate change, because it brings new upstream code into a pull_request_target workflow.

Verification

GH_TOKEN=$(gh auth token) uvx zizmor .github/workflows/auto-label.yml

With zizmor 1.30.1 (the locked version), this command reports the ref-version-mismatch finding on main and no findings with this change.

🤖 Generated with Claude Code

https://claude.ai/code/session_015fagcMeo1LmLG2Dg3NybmQ

The workflow pins codelytv/pr-size-labeler to commit 095a41f with the
comment "v1". Upstream moved its v1 tag to v1.11.1, so zizmor's
ref-version-mismatch audit now fails on each pull request. The pinned
commit is the v1.10.4 release. Name that tag in the comment. The pinned
code does not change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015fagcMeo1LmLG2Dg3NybmQ
@thomaspinder
thomaspinder enabled auto-merge (squash) September 30, 2026 13:46
@github-actions github-actions Bot added ci Continuous Integration size/xs labels Sep 30, 2026
@github-actions

Copy link
Copy Markdown

📖 Docs preview: https://pr-797--endearing-crepe-c2d5fe.netlify.app

Smoke render — the expensive notebooks run with reduced budgets, so
figures are not publication fidelity. /render-mode.txt says smoke.

@thomaspinder
thomaspinder merged commit df36145 into main Sep 30, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Continuous Integration size/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant