ci: add merge_group and drop policy caller (PLAT-108) (#125)
Some checks are pending
ci / ci / ci (push) Waiting to run

* ci: add merge_group trigger for required ci / ci

* ci: drop this repo's PR policy caller
This commit is contained in:
Adam Moussa 2026-08-21 17:41:23 -04:00 • committed by GitHub
parent af0f002e14
commit 8ec1f627fe
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
10 changed files with 8 additions and 24 deletions

View file

@ -41,6 +41,7 @@ on:
pull_request:
push:
branches: [main]
merge_group:
permissions:
contents: read

View file

@ -1,22 +0,0 @@
name: PR Policy
on:
pull_request:
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
concurrency:
group: "policy-${{ github.event.pull_request.number }}"
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}

View file

@ -64,8 +64,6 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl
**`.github/workflows/release-on-merge.yaml`** — Repo automation (not callable): cuts a tag and GitHub Release for **this** repo whenever a merge to `main` changes a reusable workflow, so Dependabot has a release to advance consumer SHA pins to (see the pinning policy below).
**`.github/workflows/policy.yaml`** — This repo's own thin caller of `callable-pr-policy.yaml`, so the PR policy gate runs on `.github`'s own PRs. Pinned to the remote SHA at v1.0.5; a local `./` path reference is rejected by the supply-chain gate. The Jira org secrets (`JIRA_CLOUD_ID`, `JIRA_SERVICE_ACCOUNT_EMAIL`, `JIRA_API_TOKEN`) must be granted to this repo before human PRs that include a Jira key can pass the existence check. Dependabot-authored PRs skip the gate.
**`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs.
**`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted.

View file

@ -2,6 +2,7 @@ name: CI (.NET)
on:
pull_request:
branches: [main]
merge_group:
jobs:
ci:

View file

@ -2,6 +2,7 @@ name: CI (Mobile / iOS)
on:
pull_request:
branches: [main]
merge_group:
jobs:
ci:

View file

@ -2,6 +2,7 @@ name: CI (Node / TypeScript)
on:
pull_request:
branches: [main]
merge_group:
jobs:
ci:

View file

@ -2,6 +2,7 @@ name: CI (Python / app)
on:
pull_request:
branches: [main]
merge_group:
jobs:
ci:

View file

@ -2,6 +2,7 @@ name: CI (Python / SAM)
on:
pull_request:
branches: [main]
merge_group:
jobs:
ci:

View file

@ -2,6 +2,7 @@ name: CI (Static Site)
on:
pull_request:
branches: [main]
merge_group:
jobs:
ci:

View file

@ -2,6 +2,7 @@ name: CI (TypeScript / frontend)
on:
pull_request:
branches: [main]
merge_group:
jobs:
ci: