fix(ci): keep a temporary ci / ci alias until the ruleset cutover

This commit is contained in:
Adam Moussa 2026-10-05 17:43:02 -04:00
parent 97e42170e9
commit 2c10f40567
2 changed files with 23 additions and 1 deletions

View file

@ -19,6 +19,11 @@ name: ci
# the check-run name IS the job name, so the aggregator is named literally
# "ci-complete". Do not put the portion job names in a ruleset.
#
# The trailing `ci` job (check-run name "ci / ci") is temporary. Until the org
# ruleset cutover moves this repo from "main branch protection" onto "CI
# complete", main still requires `ci / ci`; that job mirrors `ci-complete` so
# the legacy context stays satisfiable. Drop it after the cutover.
#
# actionlint is pinned to a tagged release and installed by downloading the
# release tarball and verifying its SHA256 — not `curl | bash` — to keep the
# supply-chain surface auditable. Bump ACTIONLINT_VERSION + ACTIONLINT_SHA256
@ -98,3 +103,20 @@ jobs:
set -euo pipefail
test "${ISOLATION_TESTS}" = success
test "${ACTIONLINT}" = success
# Temporary legacy context for main branch protection. `always()` plus the
# explicit result test matter: a skipped required check counts as passing,
# so this must run and fail whenever ci-complete does not succeed.
ci:
name: ci / ci
needs: ci-complete
if: always() && !cancelled()
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Mirror ci-complete
env:
CI_COMPLETE: ${{ needs.ci-complete.result }}
run: |
set -euo pipefail
test "${CI_COMPLETE}" = success

View file

@ -89,7 +89,7 @@ The formatter GitHub App is not on the main-branch bypass list.
**`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs.
**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted.
**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. A temporary `ci` job mirrors `ci-complete` as `ci / ci` until this repo's ruleset cutover lands; drop it afterwards. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted.
### Workflow templates (`workflow-templates/`)