Merge branch 'main' into dependabot/github_actions/actions/setup-python-6

This commit is contained in:
Adam Moussa 2026-06-16 15:59:54 -04:00 • committed by GitHub
commit c2735defa0
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
7 changed files with 90 additions and 5 deletions

View file

@ -73,7 +73,7 @@ jobs:
cache: npm
cache-dependency-path: ${{ inputs.cache-dependency-path }}
- uses: ruby/setup-ruby@12fd324f1d0b43274fdc8130f6980590a667c455 # v1
- uses: ruby/setup-ruby@89f90524b88a01fe6e0b732220432cc6142926af # v1
with:
ruby-version: ${{ inputs.ruby-version }}
bundler-cache: true

View file

@ -46,7 +46,7 @@ jobs:
with:
python-version: ${{ inputs.python-version }}
- uses: aws-actions/setup-sam@v2
- uses: aws-actions/setup-sam@v3
- uses: aws-actions/configure-aws-credentials@v6
with:

View file

@ -147,7 +147,7 @@ jobs:
- name: Setup SAM CLI
if: ${{ inputs.run-sam-validate }}
uses: aws-actions/setup-sam@v2
uses: aws-actions/setup-sam@v3
- name: SAM validate
if: ${{ inputs.run-sam-validate }}

View file

@ -156,7 +156,7 @@ jobs:
- name: Setup SAM CLI
if: ${{ inputs.run-sam-validate }}
uses: aws-actions/setup-sam@v2
uses: aws-actions/setup-sam@v3
- name: SAM validate
if: ${{ inputs.run-sam-validate }}

60
.github/workflows/ci.yaml vendored Normal file
View file

@ -0,0 +1,60 @@
name: ci
# Self-CI for this org `.github` repo.
#
# The org ruleset "main branch protection" requires the `ci / ci` status check on
# every repo. Consumer repos satisfy it via a short caller workflow that invokes
# the reusable workflows here. This repo only HOUSES those reusable workflows
# (all `workflow_call`-only), so nothing emitted `ci / ci` and every PR sat
# permanently "Expected — Waiting for status to be reported" and could not merge.
#
# This workflow produces that check by linting the workflow files with actionlint
# — genuinely useful CI for a repo whose whole product is GitHub Actions YAML.
#
# Naming is load-bearing: the ruleset matches the required status check against
# the JOB's check-run name, NOT "workflow / job". For a normal (non-reusable) job
# the check-run name IS the job name, so the job must be named literally "ci / ci"
# to emit that exact context. (A job named "ci" emits the context "ci" — which the
# PR UI cosmetically *displays* as "ci / ci" but does NOT satisfy the requirement.)
# This mirrors the org's aggregator-job convention.
#
# actionlint is pinned to a tagged release and installed by downloading the
# release tarball and verifying its SHA256 — not `curl | bash` — to keep the
# supply-chain surface auditable. Bump ACTIONLINT_VERSION + ACTIONLINT_SHA256
# together (checksum from the release's *_checksums.txt).
#
# actionlint's shellcheck integration is disabled (`-shellcheck=`) for now: it
# reports 4 pre-existing findings in the deploy/CI run-steps (SC2044 find-in-for
# loops, SC2046/SC2086 quoting, one of which is intentional word-splitting in the
# SAM deploy step). Those deserve a separate, tested cleanup rather than being
# bundled into the gate that unblocks the repo. Re-enable shellcheck once fixed.
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
jobs:
ci:
name: ci / ci
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: Install actionlint
env:
ACTIONLINT_VERSION: 1.7.12
ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
run: |
curl -fsSL -o actionlint.tar.gz \
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c -
tar -xzf actionlint.tar.gz actionlint
shell: bash
- name: Lint workflows
run: ./actionlint -color -shellcheck=
shell: bash

View file

@ -76,7 +76,7 @@ jobs:
- name: Run compliance audit
id: audit
uses: anthropics/claude-code-action@0f97b95b6536c26e5f6bd90faec370d41695beca # v1
uses: anthropics/claude-code-action@4d7e1f0cd85743fdc93b1c8040ab54395da024e2 # v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: |

25
.github/workflows/labeler.yaml vendored Normal file
View file

@ -0,0 +1,25 @@
name: labeler
# Thin caller that runs the org-wide reusable PR labeler (callable-labeler.yaml)
# on THIS repo's own pull requests. The .github repo is the single source of truth
# for the reusable workflows, but — like any consumer repo — it must invoke them
# via a caller to use them on itself; without this, the labeler never runs on
# .github's own PRs (the reusable is `workflow_call`-only).
#
# Permissions are load-bearing: callers MUST grant all three below. Reusable-
# workflow permissions can only be downgraded from the caller, so omitting one
# (e.g. issues:write) either fails to create labels or triggers a silent
# startup_failure. `pull_request` (NOT pull_request_target) is correct here — the
# org takes no fork PRs, so the lower-privilege event is sufficient.
on:
pull_request:
permissions:
contents: read
pull-requests: write
issues: write
jobs:
label:
uses: ./.github/workflows/callable-labeler.yaml