fix(actions): validate composite dependencies under native runner locking - #6
Conversation
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (5)
📝 SummarySummary by CodeRabbit
WalkthroughThe changes update workflow metadata and action references. They add a test timeout, replace local action paths, update checkout references, and change manifest validators to use their ChangesWorkflow maintenance
Estimated code review effort: 2 (Simple) | ~10 minutes Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. I hop through workflows, neat and bright Comment |
|



Fraying PR #65 passed gh actions-lock verification but GitHub rejected startup because the nested K9 SHA reference had no matching runtime lock entry. Align nested validator refs with the native locked references, and onboard the suite self-tests and estate audit to GitHub action locking. The same composite gate now exercises valid A2ML/K9 fixtures and deliberate failures with runtime lock enforcement active. Full authoritative lock verification passes for all four workflows. This follows #5 and preserves real validator failures.