Distinguish ./ From $/ Resolution in the Pin Rule's Prose - #1888
Conversation
A $/ reference resolves at the containing workflow file's commit, while a ./ action reference resolves against whatever the job checked out, which inside a cross-repository reusable workflow is the caller's checkout. State the difference in scripts/README.md's sha-pin bullet and in WORKFLOW.md's test-methodology trace paragraph, and regenerate the skill copies that include the latter. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A job-level ./ reusable-workflow call resolves at the calling workflow file's commit, like $/, and a ./ action reference names the caller's tree only where the reusable workflow checks out its caller. Align check_sha_pin's docstring with the same distinction. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: ptr727/ProjectTemplate/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The updated check_sha_pin docstring still does not fully match the implementation because .github/ refs are also skipped but not documented as such.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This PR updates the fleet's action pinning documentation to distinguish how ./ vs $/ uses: references resolve when tracing workflows, particularly in reusable workflows called from another repository.
Changes:
- Clarifies in
WORKFLOW.mdthat$/(and job-level./reusable-workflow calls) resolve at the calling workflow file's commit, while./action references resolve against the job's checked-out tree. - Updates the
sha-pincheck description inscripts/README.mdto reflect the same distinction. - Regenerates the
workflow-ci-contractskill copies and updates the plugin source digest; adjusts thecheck_sha_pindocstring wording (behavior unchanged).
| File | Description |
|---|---|
| WORKFLOW.md | Refines trace methodology prose to differentiate ./ vs $/ resolution points. |
| scripts/README.md | Updates sha-pin rule prose to describe resolution differences between ./ and $/. |
| .github/skills/workflow-ci-contract/references/test-methodology.md | Regenerated copy of the updated trace methodology text. |
| .github/actions/repo-gate/repo_gate.py | Docstring wording update for check_sha_pin (no behavior change). |
| .claude-plugin/fleet-skills/skills/workflow-ci-contract/references/test-methodology.md | Regenerated plugin copy of the updated trace methodology text. |
| .claude-plugin/fleet-skills/.source-digests/workflow-ci-contract | Updates the recorded source digest for the regenerated skill content. |
| .agents/skills/workflow-ci-contract/references/test-methodology.md | Source skill reference content updated via include regeneration. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
check_sha_pin also skips a ref starting with a bare .github/ path, so its docstring and the scripts/README.md sha-pin bullet list that form beside ./ and $/. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…File's Commit A bare .github/ ref is not a local reference GitHub accepts, so the sha-pin prose names it as a form the check skips without validating rather than as a local reference (#1889 tracks the code). The tracing sentence now traces a $/ or job-level ./ callee at its calling file's own commit rather than at the outermost pin, which it contradicted. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…and Overnight Fixes to Main (#1850) Promotes `develop` to `main`. ## Carried - #1846: exits `repo-config/configure.sh` early, writing nothing, for a repository whose registry `status` is `archived`. - #1848: fails the validator's C# unit test step when the run wrote no non-empty Cobertura report, clearing `./coverage` first. It declines #1134's `ref` input with evidence, since a bare checkout already validates `github.sha`, and D1.2 now says so. #1134's third gap moved to #1800. - #1851: asserts that the two planted registration defects are themselves reported. - #1854, #1858: correct #1846's test docstrings, which claimed the script makes no `gh` call before the archived check in cases where it does. Raised by Copilot on this pull request. - #1856: passes `--repo` on documented handoff commands and guards handoff reads against a full page, per #1847. - #1859, #1863: fall back to the default search path when `PATH` is unset in #1848's and #1846's test harnesses. Raised by Copilot on this pull request. - #1861: scopes `VerifyReferenceAotCompatibility` to an AOT publish in `dotnet-codestyle`, per #1857. - #1867: establishes the `PATH` order `tool_shadow_path` names, per #1644. - #1870: makes the installer's dirty-checkout tests independent of the real checkout's state, per #1641. - #1873: pins and decodes git's quoting in `repo_gate.py`'s `ls-files` read, per #1580 and #1872. - #1878: folds typographic punctuation in `pr_review.py reply --match`, per #1299. - #1883: routes `configure.sh`'s `ruleset_id()` through `jqr`, per #1253. - #1885: states the pin comment as the release tag and defines `$/`, per #1805. - #1888: distinguishes `./` from `$/` resolution in the pin rule's prose, per #1886. - #1893: drops the issue reference from `repo-config/README.md`'s archived-exemption note, which Copilot flagged on six rounds of this pull request. - #1895: describes IL3058 in `dotnet-codestyle` as a referenced assembly lacking `IsAotCompatible` metadata set to `true`, and drops the unversioned package examples. Raised by CodeRabbit on this pull request. Callers that pin a hub release get the new C# check on their next pin bump. A test project that runs `dotnet test --coverage` without writing a report now fails its step rather than passing silently. Closes #1134 Closes #1847 Closes #1857 Closes #1644 Closes #1641 Closes #1580 Closes #1872 Closes #1299 Closes #1253 Closes #1805 Closes #1886 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Backlog counts and rankings now consistently exclude handoff issues, including those also marked blocked. * Repository configuration commands now exit without writing when a repository is archived. * Review-thread matching handles typographic punctuation, and no-match responses report the unresolved-thread count. * Tool setup handles PATH entries more precisely, and repository checks report unusual file paths without crashing. * **Reliability** * Validation now fails when C# or Python tests produce no coverage report. * Agent setup can use an explicit dirty-checkout override. * Workflow and repository guidance clarifies reference resolution, release-tag pinning, and AOT configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai -->

Summary
The pin rule's prose said local (
./) and self-repository ($/) references both "run at the workflow commit". That holds for$/and for a job-level./reusable-workflow call, which GitHub resolves at the calling workflow file's commit. It does not hold for a./action reference, which resolves against whatever the job checked out, the caller's tree where a reusable workflow called from another repository checks out its caller.scripts/README.md: thesha-pinbullet states the distinction.WORKFLOW.md: the test-methodology trace paragraph states which commit each form is traced at. The three generated skill copies are regenerated..github/actions/repo-gate/repo_gate.py: thecheck_sha_pindocstring no longer claims a local ref names the running commit. Behavior is unchanged.Two local strict review passes ran: the first raised four findings, all fixed in da78261, and the second raised none.
Closes on promotion: #1886
🤖 Generated with Claude Code