From 2f25ac3535e35ac8b66592a339e7e456bdfc5722 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 16 Jun 2026 15:09:48 -0400 Subject: [PATCH 1/4] Add self-CI actionlint gate to satisfy ci/ci ruleset MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The org ruleset requires the 'ci / ci' status check on every repo, but this .github repo only houses reusable (workflow_call) workflows and emitted no such check — so every PR sat 'Expected — Waiting for status to be reported' and was unmergeable, including the open Dependabot bumps (#58, #59, #60). Add a workflow that runs actionlint (pinned, checksum-verified) over the workflow files. The ruleset matches the required check against the JOB's check-run name, so the job is named literally 'ci / ci' to emit that exact context (a job named 'ci' emits context 'ci', which the UI only cosmetically shows as 'ci / ci'). shellcheck integration is disabled for now; 4 pre-existing run-step findings are left for a separate cleanup. Pre-existing checkov IAM findings in oidc-deploy-roles.yaml are accepted-risk and suppressed via machine-level security-review config, intentionally NOT committed to this repo. --- .github/workflows/ci.yaml | 60 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) create mode 100644 .github/workflows/ci.yaml diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml new file mode 100644 index 0000000..5b31360 --- /dev/null +++ b/.github/workflows/ci.yaml @@ -0,0 +1,60 @@ +name: ci + +# Self-CI for this org `.github` repo. +# +# The org ruleset "main branch protection" requires the `ci / ci` status check on +# every repo. Consumer repos satisfy it via a short caller workflow that invokes +# the reusable workflows here. This repo only HOUSES those reusable workflows +# (all `workflow_call`-only), so nothing emitted `ci / ci` and every PR sat +# permanently "Expected — Waiting for status to be reported" and could not merge. +# +# This workflow produces that check by linting the workflow files with actionlint +# — genuinely useful CI for a repo whose whole product is GitHub Actions YAML. +# +# Naming is load-bearing: the ruleset matches the required status check against +# the JOB's check-run name, NOT "workflow / job". For a normal (non-reusable) job +# the check-run name IS the job name, so the job must be named literally "ci / ci" +# to emit that exact context. (A job named "ci" emits the context "ci" — which the +# PR UI cosmetically *displays* as "ci / ci" but does NOT satisfy the requirement.) +# This mirrors the org's aggregator-job convention. +# +# actionlint is pinned to a tagged release and installed by downloading the +# release tarball and verifying its SHA256 — not `curl | bash` — to keep the +# supply-chain surface auditable. Bump ACTIONLINT_VERSION + ACTIONLINT_SHA256 +# together (checksum from the release's *_checksums.txt). +# +# actionlint's shellcheck integration is disabled (`-shellcheck=`) for now: it +# reports 4 pre-existing findings in the deploy/CI run-steps (SC2044 find-in-for +# loops, SC2046/SC2086 quoting, one of which is intentional word-splitting in the +# SAM deploy step). Those deserve a separate, tested cleanup rather than being +# bundled into the gate that unblocks the repo. Re-enable shellcheck once fixed. + +on: + pull_request: + push: + branches: [main] + +permissions: + contents: read + +jobs: + ci: + name: ci / ci + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + + - name: Install actionlint + env: + ACTIONLINT_VERSION: 1.7.12 + ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 + run: | + curl -fsSL -o actionlint.tar.gz \ + "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" + echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c - + tar -xzf actionlint.tar.gz actionlint + shell: bash + + - name: Lint workflows + run: ./actionlint -color -shellcheck= + shell: bash From 9353a212c307a132272310a792c8c6ca1b5abd63 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 16 Jun 2026 15:50:09 -0400 Subject: [PATCH 2/4] Run the org PR labeler on .github's own PRs Add a thin caller so the .github repo invokes its own reusable callable-labeler.yaml on pull_request, like every consumer repo does. Without a caller the workflow_call-only labeler never runs on .github's own PRs (this is why #61 wasn't auto-labeled). Grants the three permissions the reusable requires (contents:read, pull-requests:write, issues:write). --- .github/workflows/labeler.yaml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 .github/workflows/labeler.yaml diff --git a/.github/workflows/labeler.yaml b/.github/workflows/labeler.yaml new file mode 100644 index 0000000..6f3a8c0 --- /dev/null +++ b/.github/workflows/labeler.yaml @@ -0,0 +1,25 @@ +name: labeler + +# Thin caller that runs the org-wide reusable PR labeler (callable-labeler.yaml) +# on THIS repo's own pull requests. The .github repo is the single source of truth +# for the reusable workflows, but — like any consumer repo — it must invoke them +# via a caller to use them on itself; without this, the labeler never runs on +# .github's own PRs (the reusable is `workflow_call`-only). +# +# Permissions are load-bearing: callers MUST grant all three below. Reusable- +# workflow permissions can only be downgraded from the caller, so omitting one +# (e.g. issues:write) either fails to create labels or triggers a silent +# startup_failure. `pull_request` (NOT pull_request_target) is correct here — the +# org takes no fork PRs, so the lower-privilege event is sufficient. + +on: + pull_request: + +permissions: + contents: read + pull-requests: write + issues: write + +jobs: + label: + uses: ./.github/workflows/callable-labeler.yaml From 828187d5bd4cc016bc1bb754f3666dfd4913d918 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 16 Jun 2026 19:55:52 +0000 Subject: [PATCH 3/4] Bump the minor-and-patch group across 1 directory with 2 updates Bumps the minor-and-patch group with 2 updates in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action). Updates `ruby/setup-ruby` from 1.312.0 to 1.313.0 - [Release notes](https://github.com/ruby/setup-ruby/releases) - [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb) - [Commits](https://github.com/ruby/setup-ruby/compare/12fd324f1d0b43274fdc8130f6980590a667c455...89f90524b88a01fe6e0b732220432cc6142926af) Updates `anthropics/claude-code-action` from 1.0.144 to 1.0.149 - [Release notes](https://github.com/anthropics/claude-code-action/releases) - [Commits](https://github.com/anthropics/claude-code-action/compare/0f97b95b6536c26e5f6bd90faec370d41695beca...4d7e1f0cd85743fdc93b1c8040ab54395da024e2) --- updated-dependencies: - dependency-name: anthropics/claude-code-action dependency-version: 1.0.148 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: ruby/setup-ruby dependency-version: 1.313.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/cd-mobile-ios.yaml | 2 +- .github/workflows/compliance-audit.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/cd-mobile-ios.yaml b/.github/workflows/cd-mobile-ios.yaml index 4a808f7..8f553b9 100644 --- a/.github/workflows/cd-mobile-ios.yaml +++ b/.github/workflows/cd-mobile-ios.yaml @@ -73,7 +73,7 @@ jobs: cache: npm cache-dependency-path: ${{ inputs.cache-dependency-path }} - - uses: ruby/setup-ruby@12fd324f1d0b43274fdc8130f6980590a667c455 # v1 + - uses: ruby/setup-ruby@89f90524b88a01fe6e0b732220432cc6142926af # v1 with: ruby-version: ${{ inputs.ruby-version }} bundler-cache: true diff --git a/.github/workflows/compliance-audit.yaml b/.github/workflows/compliance-audit.yaml index 96c4409..39b7ea6 100644 --- a/.github/workflows/compliance-audit.yaml +++ b/.github/workflows/compliance-audit.yaml @@ -76,7 +76,7 @@ jobs: - name: Run compliance audit id: audit - uses: anthropics/claude-code-action@0f97b95b6536c26e5f6bd90faec370d41695beca # v1 + uses: anthropics/claude-code-action@4d7e1f0cd85743fdc93b1c8040ab54395da024e2 # v1 with: anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }} prompt: | From 6333d5cc344afe4975c6ea34ce062477c04afdbf Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 16 Jun 2026 19:57:39 +0000 Subject: [PATCH 4/4] Bump aws-actions/setup-sam from 2 to 3 Bumps [aws-actions/setup-sam](https://github.com/aws-actions/setup-sam) from 2 to 3. - [Release notes](https://github.com/aws-actions/setup-sam/releases) - [Commits](https://github.com/aws-actions/setup-sam/compare/v2...v3) --- updated-dependencies: - dependency-name: aws-actions/setup-sam dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/cd-sam.yaml | 2 +- .github/workflows/ci-python-sam.yaml | 2 +- .github/workflows/ci-typescript-cdk.yaml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/cd-sam.yaml b/.github/workflows/cd-sam.yaml index 4be533d..6d1f1ab 100644 --- a/.github/workflows/cd-sam.yaml +++ b/.github/workflows/cd-sam.yaml @@ -46,7 +46,7 @@ jobs: with: python-version: ${{ inputs.python-version }} - - uses: aws-actions/setup-sam@v2 + - uses: aws-actions/setup-sam@v3 - uses: aws-actions/configure-aws-credentials@v6 with: diff --git a/.github/workflows/ci-python-sam.yaml b/.github/workflows/ci-python-sam.yaml index 8aff356..cdbbcca 100644 --- a/.github/workflows/ci-python-sam.yaml +++ b/.github/workflows/ci-python-sam.yaml @@ -147,7 +147,7 @@ jobs: - name: Setup SAM CLI if: ${{ inputs.run-sam-validate }} - uses: aws-actions/setup-sam@v2 + uses: aws-actions/setup-sam@v3 - name: SAM validate if: ${{ inputs.run-sam-validate }} diff --git a/.github/workflows/ci-typescript-cdk.yaml b/.github/workflows/ci-typescript-cdk.yaml index 03a080d..00241bb 100644 --- a/.github/workflows/ci-typescript-cdk.yaml +++ b/.github/workflows/ci-typescript-cdk.yaml @@ -156,7 +156,7 @@ jobs: - name: Setup SAM CLI if: ${{ inputs.run-sam-validate }} - uses: aws-actions/setup-sam@v2 + uses: aws-actions/setup-sam@v3 - name: SAM validate if: ${{ inputs.run-sam-validate }}