From 2c10f40567d3a7580e68525985dce0ce01bcdbc8 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 5 Oct 2026 17:43:02 -0400 Subject: [PATCH] fix(ci): keep a temporary ci / ci alias until the ruleset cutover --- .github/workflows/ci.yaml | 22 ++++++++++++++++++++++ README.md | 2 +- 2 files changed, 23 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 60c1150..7604166 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -19,6 +19,11 @@ name: ci # the check-run name IS the job name, so the aggregator is named literally # "ci-complete". Do not put the portion job names in a ruleset. # +# The trailing `ci` job (check-run name "ci / ci") is temporary. Until the org +# ruleset cutover moves this repo from "main branch protection" onto "CI +# complete", main still requires `ci / ci`; that job mirrors `ci-complete` so +# the legacy context stays satisfiable. Drop it after the cutover. +# # actionlint is pinned to a tagged release and installed by downloading the # release tarball and verifying its SHA256 — not `curl | bash` — to keep the # supply-chain surface auditable. Bump ACTIONLINT_VERSION + ACTIONLINT_SHA256 @@ -98,3 +103,20 @@ jobs: set -euo pipefail test "${ISOLATION_TESTS}" = success test "${ACTIONLINT}" = success + + # Temporary legacy context for main branch protection. `always()` plus the + # explicit result test matter: a skipped required check counts as passing, + # so this must run and fail whenever ci-complete does not succeed. + ci: + name: ci / ci + needs: ci-complete + if: always() && !cancelled() + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - name: Mirror ci-complete + env: + CI_COMPLETE: ${{ needs.ci-complete.result }} + run: | + set -euo pipefail + test "${CI_COMPLETE}" = success diff --git a/README.md b/README.md index aabc1e1..04c25c5 100644 --- a/README.md +++ b/README.md @@ -89,7 +89,7 @@ The formatter GitHub App is not on the main-branch bypass list. **`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs. -**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted. +**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. A temporary `ci` job mirrors `ci-complete` as `ci / ci` until this repo's ruleset cutover lands; drop it afterwards. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted. ### Workflow templates (`workflow-templates/`)