Skip to content

ci: enforce workflow policy - #12

Merged
fvaleye merged 1 commit into
altertable-ai:mainfrom
albert20260301:ci/workflow-policy-20260809
Aug 10, 2026
Merged

ci: enforce workflow policy#12
fvaleye merged 1 commit into
altertable-ai:mainfrom
albert20260301:ci/workflow-policy-20260809

Conversation

@albert20260301

Copy link
Copy Markdown
Contributor

Summary

  • move Linux workflow jobs to ubuntu-24.04
  • pin every third-party action to its reviewed commit SHA
  • replace the duplicate legacy semantic workflow with the managed canonical workflow

Impact

This is CI-only. It preserves the existing Python version matrix, test commands, release configuration, and PyPI trusted-publishing permissions.

Validation

  • bash /root/.openclaw/workspace/scripts/validate-workflow-policy.sh /root/.openclaw/workspace/code/altertable-python-workflow-policy-20260809
  • canonical semantic-workflow comparison
  • git diff --check
  • local poetry run pytest was unavailable because Poetry is not installed in this maintenance environment; repository CI is required before merge.

@albert20260301

Copy link
Copy Markdown
Contributor Author

@fvaleye could you review this?

I picked you because the product Python repository's existing community-sync work has your approval and Python is in your ownership area. CI is pending. The main review focus is that the runner and immutable-action updates preserve the existing Python matrix and trusted-publishing flow.

@fvaleye
fvaleye merged commit 284e327 into altertable-ai:main Aug 10, 2026
10 checks passed
@albert20260301
albert20260301 deleted the ci/workflow-policy-20260809 branch August 10, 2026 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants