You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Changed
CI: the Gourmand job reports as Code Quality (Gourmand) / Code Quality (Gourmand) like the rest of the fleet, so the org ruleset can require it.
Constitution is now a v1.18.0 manifest: purpose, CLI and workflow contract,
external API, agents and ignored paths; fleet and profile rules apply by
reference.
Constitution validation pinned to v1.18.0 via constitution.yml, replacing
the unpinned validation job in ci.yml.
Dependabot auto-merges GitHub Actions minor and patch updates.
Fixed
Reviewers no longer flag a version, tag or release as nonexistent. Every
Dependabot bump to a major newer than the model's cutoff (checkout@v7,
setup-python@v7, ...) drew a "tag does not exist" finding, repeated on
each rebase.
examples/gourmand.yml pinned gourmand.yml@v0.5.0 and was a bare job
fragment. It is now a complete workflow on pull_request at the current
release, and a test fails any example that pins a different release than
the one it ships in (crunchtools/constitution#22).