)]}'
{
  "commit": "f0952f3c5c91bef2d686bbe62d6041908012731e",
  "tree": "659020cd0aa6e309e0d0f9fa6c58ca7e682f45cc",
  "parents": [
    "8b6fef24f56fb2de4489a0003dd3526068df48f5"
  ],
  "author": {
    "name": "Greg Magolan",
    "email": "gmagolan@gmail.com",
    "time": "Sun May 31 22:20:31 2026 -0700"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Sun May 31 22:20:31 2026 -0700"
  },
  "message": "ci: adopt aspect-build/setup-aspect (#2870)\n\nReplace `bazel-contrib/setup-bazel` + manual `curl install.aspect.build`\n+ top-level `ASPECT_API_TOKEN`/`ASPECT_LAUNCHER_VERSION` env vars with\n[`aspect-build/setup-aspect@v2026.23.2`](https://github.com/aspect-build/setup-aspect/releases/tag/v2026.23.2).\n\nThe action handles in one step:\n- Launcher + Bazelisk install (no-op when `bazel` is already on PATH,\ne.g. Workflows runners)\n- `bazelisk-cache` / `disk-cache` / `repository-cache` wiring on\nephemeral runners\n- `aspect auth login --with-api-token` to exchange the long-lived secret\nfor a short-lived JWT — the raw token no longer leaks into every step\u0027s\nenv\n\n`ci-vanilla-bazel.yaml` is intentionally left alone.\n\n---\n\n### Changes are visible to end-users: no\n\n### Test plan\n\n- Covered by existing test cases\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "01d2262d9f4f19f8f0a5ba814164346554bc29a0",
      "old_mode": 33188,
      "old_path": ".github/workflows/ci-workflows.yaml",
      "new_id": "6a0deef433c0a39f65fe64430d57f4b73180a4fb",
      "new_mode": 33188,
      "new_path": ".github/workflows/ci-workflows.yaml"
    }
  ]
}
