Skip to content

docs: correct v2.3.0 pin and attestation fallback - #179

Merged
nicolasparada merged 1 commit into
mainfrom
docs/pnpm-v230-pin-attestation-20261002
Oct 6, 2026
Merged

nicolasparada merged 1 commit into
mainfrom
docs/pnpm-v230-pin-attestation-20261002

Conversation

@jadoonf

@jadoonf jadoonf commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Correct the exact v2.3.0 SHA pin to 245ad6be82de3200c205109c8ca7ac816dc692ea.
  • Qualify the scoped-egress attestation wording: verification runs when github_token and gh are available; otherwise the Action warns and skips attestation verification.

Validation

  • npm ci — passed.
  • npm run validate — failed in test/terminal-run.test.js: exec.exec is not a function (100 passed, 1 failed); no runtime files were changed.
  • npm run typecheck — passed.
  • npm run build — passed; final diff is README-only.

Note

Low Risk
README-only changes with no runtime or workflow behavior modified.

Overview
Documentation-only updates to match how the Action actually behaves and to fix a wrong release pin.

The Scoped egress bullet now states that Jibril release attestation via gh attestation verify runs only when github_token and the gh CLI are available; otherwise the Action warns and skips attestation (checksum verification is still described as part of the flow).

The pinning example for v2.3.0 is corrected from SHA f9ed14ab… to 245ad6be82de3200c205109c8ca7ac816dc692ea.

Reviewed by Cursor Bugbot for commit 2aa21b7. Bugbot is set up for automated code reviews on this repo. Configure here.

@strix-security

strix-security Bot commented Oct 2, 2026

Copy link
Copy Markdown

Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here.

So far, Strix has reviewed 13 pull requests and surfaced 1 security issue across this workspace.

@garnet-runtime-review

garnet-runtime-review Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Execution Profiles recorded for 1 job, triggered by 2aa21b7

6 destinations
recorded at the kernel by Garnet · 2026-10-02 19:45 UTC

CI / build-and-verify ↗ · 6 destinations
Runner.Worker
├─ node
│  └─ ○ api.github[.]com
└─ bash
   └─ node (step: "Install dependencies")
      ├─ ○ localhost (dns resolver)
      └─ ○ registry.npmjs[.]org

systemd
├─ python3.12
│  └─ python3.12
│     └─ ○ 168.63.129.16
├─ hosted-compute-agent
│  └─ sudo
│     └─ provjobd (ran from /tmp/…)
│        └─ ○ hosted-compute-watchdog-prod-iad-01[.]githubapp (github infra)
└─ systemd-networkd
   └─ ○ ip6-allrouters

View this job's Execution Profile in Garnet →


💡 How to read this
Runner.Worker          ← process on a path
└─ npm
   └─ node             ← process that acted
      └─ ○ npmjs[.]org ← observed action

follow a path downward to see what ran and what it did — each path to an observed action is an execution chain

names on the path = processes · ○ = observed action · (…) = context

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@nicolasparada
nicolasparada merged commit f1ada26 into main Oct 6, 2026
6 checks passed
@nicolasparada
nicolasparada deleted the docs/pnpm-v230-pin-attestation-20261002 branch October 6, 2026 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants