The GitHub Actions job "prek" on airflow-steward.git/main has failed.
Run started by GitHub user potiuk (triggered by potiuk).

Head commit for run:
7a1941122581224bdb310bae822a241d239833e7 / Jarek Potiuk <[email protected]>
docs(secure-agent-setup): add Linux Mint 22 / Ubuntu Noble shortcut (#12)

The pinned bubblewrap (0.11.1) and socat (1.8.1.1) versions in
`tools/agent-isolation/pinned-versions.toml` are the upstream
releases that have aged past the framework's 7-day cooldown — they
are NOT in Ubuntu Noble's main repos. Noble ships:

  bubblewrap 0.9.0  (0.9.0-1ubuntu0.1)
  socat      1.8.0.0 (1.8.0.0-4build3)

Both pre-date the framework's pins by months and are well past the
cooldown, so they're a legitimate adopter choice on Mint 22.
Ubuntu 24.04 — but the framework's main install path documents the
upstream pins, which leaves Mint/Noble adopters without a cl
story.

This commit adds a *Distro-specific shortcut* section under
\`Install commands\` that:

- Documents the apt-shipped versions and their \`apt_pin\` s
- Calls out the trade-off explicitly (older feature set, but apt-
  managed security backports, no source build).
- Notes that the framework's \`.claude/settings.json\` works
  unchanged — the sandbox API has been stable since bubblewr
  0.6.x.
- Tells the user how to silence the drift the check script w
  report against the upstream pins (a \`pinned-versions.local.toml\`,
  matching Claude Code's own \`settings.local.json\` convent
- Closes with the rationale for keeping this as a "shortcut" rather
  than the canonical path.

No change to \`pinned-versions.toml\` itself — the framework
default pin still tracks the upstream release stream, which is the
right thing to track for the weekly check-tool-updates routi

Generated-by: Claude Code (Claude Opus 4.7)

Report URL: https://github.com/apache/airflow-steward/actions/runs/25112962476

With regards,
GitHub Actions via GitBox


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to