From ea0628c8d279e95ec4271bbdf9a93bbdad922101 Mon Sep 17 00:00:00 2001 From: Thomas Sprayberry <263217947+askalf@users.noreply.github.com> Date: Fri, 25 Sep 2026 14:52:45 -0400 Subject: [PATCH 1/2] ci: Redline caller pinned to askalf/askalf@35a0ee3 (#62 + #63) --- .github/workflows/redline.yml | 50 +++++++++++++++++------------------ 1 file changed, 25 insertions(+), 25 deletions(-) diff --git a/.github/workflows/redline.yml b/.github/workflows/redline.yml index 1f29f13..db06689 100644 --- a/.github/workflows/redline.yml +++ b/.github/workflows/redline.yml @@ -1,25 +1,25 @@ -# Redline, the gating code review, as this repo's CI check. The review itself lives in -# askalf/askalf (redline-review.yml): same-repo PRs only, read-only tools, verdict = pass or fail. -name: Redline - -on: - pull_request: - types: [opened, synchronize, reopened, ready_for_review] - -permissions: - contents: read - pull-requests: read - -concurrency: - group: redline-${{ github.event.pull_request.number }} - cancel-in-progress: true - -jobs: - review: - # Same-repo PRs only, and not drafts: gated here as well as in the called workflow, so a - # fork's code never reaches the self-hosted runner even if the callee changes. - if: github.event.pull_request.draft == false && github.event.pull_request.head.repo.full_name == github.repository - # Pinned so a change to the review workflow reaches this repo only through a reviewed bump here. - uses: askalf/askalf/.github/workflows/redline-review.yml@63e007ee5f514a32fbdaebaa313eacc5c44f852f # main 2026-09-25, askalf/askalf#60 - with: - runner-label: redline +# Redline, the gating code review, as this repo's CI check. The review itself lives in +# askalf/askalf (redline-review.yml): same-repo PRs only, read-only tools, verdict = pass or fail. +name: Redline + +on: + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + +permissions: + contents: read + pull-requests: read + +concurrency: + group: redline-${{ github.event.pull_request.number }} + cancel-in-progress: true + +jobs: + review: + # Same-repo PRs only, and not drafts: gated here as well as in the called workflow, so a + # fork's code never reaches the self-hosted runner even if the callee changes. + if: github.event.pull_request.draft == false && github.event.pull_request.head.repo.full_name == github.repository + # Pinned so a change to the review workflow reaches this repo only through a reviewed bump here. + uses: askalf/askalf/.github/workflows/redline-review.yml@35a0ee3805b3d0ae6df3a7ca63bfebf35a76c6af # main 2026-09-25, askalf/askalf#63 + with: + runner-label: redline From 7e470ee2088adc3fe3fea484e52afc0e925e5e97 Mon Sep 17 00:00:00 2001 From: Thomas Sprayberry <263217947+askalf@users.noreply.github.com> Date: Fri, 25 Sep 2026 14:54:12 -0400 Subject: [PATCH 2/2] ci: Redline caller pinned to askalf/askalf@35a0ee3 (#62 + #63) --- .github/workflows/redline.yml | 50 +++++++++++++++++------------------ 1 file changed, 25 insertions(+), 25 deletions(-) diff --git a/.github/workflows/redline.yml b/.github/workflows/redline.yml index db06689..c1076ac 100644 --- a/.github/workflows/redline.yml +++ b/.github/workflows/redline.yml @@ -1,25 +1,25 @@ -# Redline, the gating code review, as this repo's CI check. The review itself lives in -# askalf/askalf (redline-review.yml): same-repo PRs only, read-only tools, verdict = pass or fail. -name: Redline - -on: - pull_request: - types: [opened, synchronize, reopened, ready_for_review] - -permissions: - contents: read - pull-requests: read - -concurrency: - group: redline-${{ github.event.pull_request.number }} - cancel-in-progress: true - -jobs: - review: - # Same-repo PRs only, and not drafts: gated here as well as in the called workflow, so a - # fork's code never reaches the self-hosted runner even if the callee changes. - if: github.event.pull_request.draft == false && github.event.pull_request.head.repo.full_name == github.repository - # Pinned so a change to the review workflow reaches this repo only through a reviewed bump here. - uses: askalf/askalf/.github/workflows/redline-review.yml@35a0ee3805b3d0ae6df3a7ca63bfebf35a76c6af # main 2026-09-25, askalf/askalf#63 - with: - runner-label: redline +# Redline, the gating code review, as this repo's CI check. The review itself lives in +# askalf/askalf (redline-review.yml): same-repo PRs only, read-only tools, verdict = pass or fail. +name: Redline + +on: + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + +permissions: + contents: read + pull-requests: read + +concurrency: + group: redline-${{ github.event.pull_request.number }} + cancel-in-progress: true + +jobs: + review: + # Same-repo PRs only, and not drafts: gated here as well as in the called workflow, so a + # fork's code never reaches the self-hosted runner even if the callee changes. + if: github.event.pull_request.draft == false && github.event.pull_request.head.repo.full_name == github.repository + # Pinned so a change to the review workflow reaches this repo only through a reviewed bump here. + uses: askalf/askalf/.github/workflows/redline-review.yml@35a0ee3805b3d0ae6df3a7ca63bfebf35a76c6af # main 2026-09-25, askalf/askalf#63 + with: + runner-label: redline