From 8ec1f627fec588a60575c455014b2b5b70e86c8e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 21 Aug 2026 17:41:23 -0400 Subject: [PATCH] ci: add merge_group and drop policy caller (PLAT-108) (#125) * ci: add merge_group trigger for required ci / ci * ci: drop this repo's PR policy caller --- .github/workflows/ci.yaml | 1 + .github/workflows/policy.yaml | 22 ------------------- README.md | 2 -- workflow-templates/ci-dotnet.yml | 1 + workflow-templates/ci-mobile-ios.yml | 1 + workflow-templates/ci-node.yml | 1 + workflow-templates/ci-python-app.yml | 1 + workflow-templates/ci-python.yml | 1 + workflow-templates/ci-static.yml | 1 + workflow-templates/ci-typescript-frontend.yml | 1 + 10 files changed, 8 insertions(+), 24 deletions(-) delete mode 100644 .github/workflows/policy.yaml diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 9aa2224..e2d4a7b 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -41,6 +41,7 @@ on: pull_request: push: branches: [main] + merge_group: permissions: contents: read diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml deleted file mode 100644 index c65c4f6..0000000 --- a/.github/workflows/policy.yaml +++ /dev/null @@ -1,22 +0,0 @@ -name: PR Policy - -on: - pull_request: - types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] - -concurrency: - group: "policy-${{ github.event.pull_request.number }}" - cancel-in-progress: true - -permissions: - contents: read - issues: read - pull-requests: read - -jobs: - policy: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7 - secrets: - JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} - JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} - JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/README.md b/README.md index 4c9e4e3..76881d5 100644 --- a/README.md +++ b/README.md @@ -64,8 +64,6 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl **`.github/workflows/release-on-merge.yaml`** — Repo automation (not callable): cuts a tag and GitHub Release for **this** repo whenever a merge to `main` changes a reusable workflow, so Dependabot has a release to advance consumer SHA pins to (see the pinning policy below). -**`.github/workflows/policy.yaml`** — This repo's own thin caller of `callable-pr-policy.yaml`, so the PR policy gate runs on `.github`'s own PRs. Pinned to the remote SHA at v1.0.5; a local `./` path reference is rejected by the supply-chain gate. The Jira org secrets (`JIRA_CLOUD_ID`, `JIRA_SERVICE_ACCOUNT_EMAIL`, `JIRA_API_TOKEN`) must be granted to this repo before human PRs that include a Jira key can pass the existence check. Dependabot-authored PRs skip the gate. - **`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs. **`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted. diff --git a/workflow-templates/ci-dotnet.yml b/workflow-templates/ci-dotnet.yml index 0f0be14..9032510 100644 --- a/workflow-templates/ci-dotnet.yml +++ b/workflow-templates/ci-dotnet.yml @@ -2,6 +2,7 @@ name: CI (.NET) on: pull_request: branches: [main] + merge_group: jobs: ci: diff --git a/workflow-templates/ci-mobile-ios.yml b/workflow-templates/ci-mobile-ios.yml index b4ca371..ae929c5 100644 --- a/workflow-templates/ci-mobile-ios.yml +++ b/workflow-templates/ci-mobile-ios.yml @@ -2,6 +2,7 @@ name: CI (Mobile / iOS) on: pull_request: branches: [main] + merge_group: jobs: ci: diff --git a/workflow-templates/ci-node.yml b/workflow-templates/ci-node.yml index 3e8e1fb..1a31874 100644 --- a/workflow-templates/ci-node.yml +++ b/workflow-templates/ci-node.yml @@ -2,6 +2,7 @@ name: CI (Node / TypeScript) on: pull_request: branches: [main] + merge_group: jobs: ci: diff --git a/workflow-templates/ci-python-app.yml b/workflow-templates/ci-python-app.yml index 363785b..3f4a49d 100644 --- a/workflow-templates/ci-python-app.yml +++ b/workflow-templates/ci-python-app.yml @@ -2,6 +2,7 @@ name: CI (Python / app) on: pull_request: branches: [main] + merge_group: jobs: ci: diff --git a/workflow-templates/ci-python.yml b/workflow-templates/ci-python.yml index a3f09b2..3f347ce 100644 --- a/workflow-templates/ci-python.yml +++ b/workflow-templates/ci-python.yml @@ -2,6 +2,7 @@ name: CI (Python / SAM) on: pull_request: branches: [main] + merge_group: jobs: ci: diff --git a/workflow-templates/ci-static.yml b/workflow-templates/ci-static.yml index 78127ea..c1f6f36 100644 --- a/workflow-templates/ci-static.yml +++ b/workflow-templates/ci-static.yml @@ -2,6 +2,7 @@ name: CI (Static Site) on: pull_request: branches: [main] + merge_group: jobs: ci: diff --git a/workflow-templates/ci-typescript-frontend.yml b/workflow-templates/ci-typescript-frontend.yml index 14d5649..1f27af9 100644 --- a/workflow-templates/ci-typescript-frontend.yml +++ b/workflow-templates/ci-typescript-frontend.yml @@ -2,6 +2,7 @@ name: CI (TypeScript / frontend) on: pull_request: branches: [main] + merge_group: jobs: ci: