Merge pull request #61 from Sea-Haven-Industries/ci-actionlint-gate

Wire .github to consume its own reusables: self-CI ci/ci gate + PR labeler
This commit is contained in:
Adam Moussa 2026-06-16 15:52:35 -04:00 • committed by GitHub
commit 9bdf7a4063
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 85 additions and 0 deletions

60
.github/workflows/ci.yaml vendored Normal file
View file

@ -0,0 +1,60 @@
name: ci
# Self-CI for this org `.github` repo.
#
# The org ruleset "main branch protection" requires the `ci / ci` status check on
# every repo. Consumer repos satisfy it via a short caller workflow that invokes
# the reusable workflows here. This repo only HOUSES those reusable workflows
# (all `workflow_call`-only), so nothing emitted `ci / ci` and every PR sat
# permanently "Expected — Waiting for status to be reported" and could not merge.
#
# This workflow produces that check by linting the workflow files with actionlint
# — genuinely useful CI for a repo whose whole product is GitHub Actions YAML.
#
# Naming is load-bearing: the ruleset matches the required status check against
# the JOB's check-run name, NOT "workflow / job". For a normal (non-reusable) job
# the check-run name IS the job name, so the job must be named literally "ci / ci"
# to emit that exact context. (A job named "ci" emits the context "ci" — which the
# PR UI cosmetically *displays* as "ci / ci" but does NOT satisfy the requirement.)
# This mirrors the org's aggregator-job convention.
#
# actionlint is pinned to a tagged release and installed by downloading the
# release tarball and verifying its SHA256 — not `curl | bash` — to keep the
# supply-chain surface auditable. Bump ACTIONLINT_VERSION + ACTIONLINT_SHA256
# together (checksum from the release's *_checksums.txt).
#
# actionlint's shellcheck integration is disabled (`-shellcheck=`) for now: it
# reports 4 pre-existing findings in the deploy/CI run-steps (SC2044 find-in-for
# loops, SC2046/SC2086 quoting, one of which is intentional word-splitting in the
# SAM deploy step). Those deserve a separate, tested cleanup rather than being
# bundled into the gate that unblocks the repo. Re-enable shellcheck once fixed.
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
jobs:
ci:
name: ci / ci
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: Install actionlint
env:
ACTIONLINT_VERSION: 1.7.12
ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
run: |
curl -fsSL -o actionlint.tar.gz \
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c -
tar -xzf actionlint.tar.gz actionlint
shell: bash
- name: Lint workflows
run: ./actionlint -color -shellcheck=
shell: bash

25
.github/workflows/labeler.yaml vendored Normal file
View file

@ -0,0 +1,25 @@
name: labeler
# Thin caller that runs the org-wide reusable PR labeler (callable-labeler.yaml)
# on THIS repo's own pull requests. The .github repo is the single source of truth
# for the reusable workflows, but — like any consumer repo — it must invoke them
# via a caller to use them on itself; without this, the labeler never runs on
# .github's own PRs (the reusable is `workflow_call`-only).
#
# Permissions are load-bearing: callers MUST grant all three below. Reusable-
# workflow permissions can only be downgraded from the caller, so omitting one
# (e.g. issues:write) either fails to create labels or triggers a silent
# startup_failure. `pull_request` (NOT pull_request_target) is correct here — the
# org takes no fork PRs, so the lower-privilege event is sufficient.
on:
pull_request:
permissions:
contents: read
pull-requests: write
issues: write
jobs:
label:
uses: ./.github/workflows/callable-labeler.yaml