fix(#322): use PR head SHA in artifact names, not the merge SHA
Gemini adversarial review caught a real traceability defect. On a `pull_request` event, `github.sha` evaluates to the last merge commit of `refs/pull/N/merge`, not the PR head commit. That merge commit is ephemeral and is not present in branch history, so a PR artifact named with it cannot be traced back to any real commit, which defeats the acceptance criterion this change was written to satisfy. Verified against GitHub's events-that-trigger-workflows reference: "Note that GITHUB_SHA for this event is the last merge commit of the pull request merge branch." Now uses `github.event.pull_request.head.sha || github.sha`, which resolves to the PR head on pull_request events and falls back to the push SHA on pushes to dev/main. Part of epic #312, plan #321 (Phase 1).main
parent
8ea5ede1dc
commit
2ff190cee1
Loading…
Reference in new issue