From c3bdbefbbf263cf41ba337834a31e72234b2e0e1 Mon Sep 17 00:00:00 2001 From: Titus Kirch Date: Wed, 2 Sep 2026 13:53:51 +0200 Subject: [PATCH] fix(ci): pin the workflow bodies to v0.5.0 One pin across the estate. v0.5.0 lets the gate body install PHP, so a Laravel repo's Pint no longer forces the whole job to stay local, and it carries the Gate fix that reports a superseded run as cancelled rather than failed. --- .github/workflows/ci.yml | 2 +- .github/workflows/codeql.yml | 2 +- .github/workflows/fast-forward-queue.yml | 2 +- .github/workflows/promotion-pr.yml | 2 +- .github/workflows/release-please.yml | 6 +++--- 5 files changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3e86f92..95e84ea 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -22,4 +22,4 @@ permissions: jobs: check: name: CI - uses: kirchDev/workflows/.github/workflows/_ci-check.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_ci-check.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index fa019fa..4659108 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -24,4 +24,4 @@ jobs: packages: read actions: read contents: read - uses: kirchDev/workflows/.github/workflows/_codeql.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_codeql.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 diff --git a/.github/workflows/fast-forward-queue.yml b/.github/workflows/fast-forward-queue.yml index 3a72ea0..96233ba 100644 --- a/.github/workflows/fast-forward-queue.yml +++ b/.github/workflows/fast-forward-queue.yml @@ -26,7 +26,7 @@ jobs: pull-requests: read checks: read statuses: read - uses: kirchDev/workflows/.github/workflows/_fast-forward-queue.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_fast-forward-queue.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 with: pr: ${{ inputs.pr }} secrets: diff --git a/.github/workflows/promotion-pr.yml b/.github/workflows/promotion-pr.yml index 3bb50d4..17203ed 100644 --- a/.github/workflows/promotion-pr.yml +++ b/.github/workflows/promotion-pr.yml @@ -15,4 +15,4 @@ permissions: jobs: promotion-pr: name: Promotion PR - uses: kirchDev/workflows/.github/workflows/_promotion-pr.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_promotion-pr.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 4afbb4c..d66b74c 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -23,7 +23,7 @@ jobs: permissions: contents: write pull-requests: write - uses: kirchDev/workflows/.github/workflows/_release-please.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_release-please.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 with: # This repo is consumed as `kirchDev/coverage-report@`, so `@v0` has # to keep meaning "the newest v0.x.y". @@ -41,7 +41,7 @@ jobs: # NPM_TOKEN exists in this repo; npm verifies this workflow against the # trusted publisher configured on the package. id-token: write - uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 with: tag-name: ${{ needs.release-please.outputs.tag-name }} # The npm artifact is lib/, built by build:npm — not the action bundle in @@ -63,7 +63,7 @@ jobs: permissions: contents: read id-token: write - uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@bec834b87a96c8c1dbf2c7cb28f774e9173e32d7 # v0.2.0 + uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@b7bc3408448d1c0c1266e8c5fe2788c9cf120790 # v0.5.0 with: prerelease: true build-script: build:npm