Skip to content

Nightly > Main CI Remediation#712

Merged
Wikid82 merged 5 commits intodevelopmentfrom
feature/beta-release
Feb 18, 2026
Merged

Nightly > Main CI Remediation#712
Wikid82 merged 5 commits intodevelopmentfrom
feature/beta-release

Conversation

@Wikid82
Copy link
Owner

@Wikid82 Wikid82 commented Feb 18, 2026

No description provided.

renovate bot and others added 2 commits February 17, 2026 23:56
…ekly-non-major-updates

chore(deps): update github/codeql-action digest to 015d8c7 (feature/beta-release)
Copilot AI review requested due to automatic review settings February 18, 2026 00:28
@Wikid82 Wikid82 self-assigned this Feb 18, 2026
@Wikid82 Wikid82 added this to Charon Feb 18, 2026
@github-project-automation github-project-automation bot moved this to Backlog in Charon Feb 18, 2026
@Wikid82 Wikid82 added critical Must have for the release, blocks other work ci-cd labels Feb 18, 2026
@Wikid82 Wikid82 changed the title Nightly > Main Ci Remediation Nightly > Main CI Remediation Feb 18, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the github/codeql-action/upload-sarif action in the security-pr workflow from an older commit SHA (b1b1e44da9bac3c3c733dd0dbecc16d3c7889499) to a newer one (015d8c7cbcbb8e7252a7dccfe81a90aa176260b2). The PR title "Nightly > Main CI Remediation" suggests this is part of broader CI/CD maintenance work to bring the main branch workflows up to date with changes made in the nightly branch.

Changes:

  • Updated the CodeQL SARIF upload action to a newer commit SHA in the security-pr workflow

@codecov
Copy link

codecov bot commented Feb 18, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@github-actions
Copy link
Contributor

github-actions bot commented Feb 18, 2026

✅ Supply Chain Verification Results

PASSED

📦 SBOM Summary

  • Components: 1674

🔍 Vulnerability Scan

Severity Count
🔴 Critical 0
🟠 High 0
🟡 Medium 0
🟢 Low 0
Total 0

📎 Artifacts

  • SBOM (CycloneDX JSON) and Grype results available in workflow artifacts

Generated by Supply Chain Verification workflow • View Details

actions-user and others added 3 commits February 18, 2026 00:51
fix: enforce fresh nightly promotion quality gates

Ensure promotion decisions are based on current nightly HEAD evidence instead of stale workflow history.
Add native CodeQL branch triggers so security analysis runs on nightly/main promotion paths.
Convert nightly and weekly automation to dispatch required checks only when missing for the exact HEAD commit, preventing duplicate/racing runs while guaranteeing check presence.
Harden weekly health verification with retry polling so transient scheduling delays do not produce false negatives.
This reduces false blocking and ensures nightly-to-main promotion uses current, deterministic CI state.
Refs: #712
@Wikid82 Wikid82 moved this from Backlog to In Review in Charon Feb 18, 2026
@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@Wikid82 Wikid82 merged commit 3c757ec into development Feb 18, 2026
32 checks passed
@github-project-automation github-project-automation bot moved this from In Review to Done in Charon Feb 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-cd critical Must have for the release, blocks other work

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

Comments