mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-05 04:52:04 +00:00
Merge branch 'main' into dependabot/github_actions/actions/setup-python-6
This commit is contained in:
commit
c2735defa0
7 changed files with 90 additions and 5 deletions
2
.github/workflows/cd-mobile-ios.yaml
vendored
2
.github/workflows/cd-mobile-ios.yaml
vendored
|
|
@ -73,7 +73,7 @@ jobs:
|
||||||
cache: npm
|
cache: npm
|
||||||
cache-dependency-path: ${{ inputs.cache-dependency-path }}
|
cache-dependency-path: ${{ inputs.cache-dependency-path }}
|
||||||
|
|
||||||
- uses: ruby/setup-ruby@12fd324f1d0b43274fdc8130f6980590a667c455 # v1
|
- uses: ruby/setup-ruby@89f90524b88a01fe6e0b732220432cc6142926af # v1
|
||||||
with:
|
with:
|
||||||
ruby-version: ${{ inputs.ruby-version }}
|
ruby-version: ${{ inputs.ruby-version }}
|
||||||
bundler-cache: true
|
bundler-cache: true
|
||||||
|
|
|
||||||
2
.github/workflows/cd-sam.yaml
vendored
2
.github/workflows/cd-sam.yaml
vendored
|
|
@ -46,7 +46,7 @@ jobs:
|
||||||
with:
|
with:
|
||||||
python-version: ${{ inputs.python-version }}
|
python-version: ${{ inputs.python-version }}
|
||||||
|
|
||||||
- uses: aws-actions/setup-sam@v2
|
- uses: aws-actions/setup-sam@v3
|
||||||
|
|
||||||
- uses: aws-actions/configure-aws-credentials@v6
|
- uses: aws-actions/configure-aws-credentials@v6
|
||||||
with:
|
with:
|
||||||
|
|
|
||||||
2
.github/workflows/ci-python-sam.yaml
vendored
2
.github/workflows/ci-python-sam.yaml
vendored
|
|
@ -147,7 +147,7 @@ jobs:
|
||||||
|
|
||||||
- name: Setup SAM CLI
|
- name: Setup SAM CLI
|
||||||
if: ${{ inputs.run-sam-validate }}
|
if: ${{ inputs.run-sam-validate }}
|
||||||
uses: aws-actions/setup-sam@v2
|
uses: aws-actions/setup-sam@v3
|
||||||
|
|
||||||
- name: SAM validate
|
- name: SAM validate
|
||||||
if: ${{ inputs.run-sam-validate }}
|
if: ${{ inputs.run-sam-validate }}
|
||||||
|
|
|
||||||
2
.github/workflows/ci-typescript-cdk.yaml
vendored
2
.github/workflows/ci-typescript-cdk.yaml
vendored
|
|
@ -156,7 +156,7 @@ jobs:
|
||||||
|
|
||||||
- name: Setup SAM CLI
|
- name: Setup SAM CLI
|
||||||
if: ${{ inputs.run-sam-validate }}
|
if: ${{ inputs.run-sam-validate }}
|
||||||
uses: aws-actions/setup-sam@v2
|
uses: aws-actions/setup-sam@v3
|
||||||
|
|
||||||
- name: SAM validate
|
- name: SAM validate
|
||||||
if: ${{ inputs.run-sam-validate }}
|
if: ${{ inputs.run-sam-validate }}
|
||||||
|
|
|
||||||
60
.github/workflows/ci.yaml
vendored
Normal file
60
.github/workflows/ci.yaml
vendored
Normal file
|
|
@ -0,0 +1,60 @@
|
||||||
|
name: ci
|
||||||
|
|
||||||
|
# Self-CI for this org `.github` repo.
|
||||||
|
#
|
||||||
|
# The org ruleset "main branch protection" requires the `ci / ci` status check on
|
||||||
|
# every repo. Consumer repos satisfy it via a short caller workflow that invokes
|
||||||
|
# the reusable workflows here. This repo only HOUSES those reusable workflows
|
||||||
|
# (all `workflow_call`-only), so nothing emitted `ci / ci` and every PR sat
|
||||||
|
# permanently "Expected — Waiting for status to be reported" and could not merge.
|
||||||
|
#
|
||||||
|
# This workflow produces that check by linting the workflow files with actionlint
|
||||||
|
# — genuinely useful CI for a repo whose whole product is GitHub Actions YAML.
|
||||||
|
#
|
||||||
|
# Naming is load-bearing: the ruleset matches the required status check against
|
||||||
|
# the JOB's check-run name, NOT "workflow / job". For a normal (non-reusable) job
|
||||||
|
# the check-run name IS the job name, so the job must be named literally "ci / ci"
|
||||||
|
# to emit that exact context. (A job named "ci" emits the context "ci" — which the
|
||||||
|
# PR UI cosmetically *displays* as "ci / ci" but does NOT satisfy the requirement.)
|
||||||
|
# This mirrors the org's aggregator-job convention.
|
||||||
|
#
|
||||||
|
# actionlint is pinned to a tagged release and installed by downloading the
|
||||||
|
# release tarball and verifying its SHA256 — not `curl | bash` — to keep the
|
||||||
|
# supply-chain surface auditable. Bump ACTIONLINT_VERSION + ACTIONLINT_SHA256
|
||||||
|
# together (checksum from the release's *_checksums.txt).
|
||||||
|
#
|
||||||
|
# actionlint's shellcheck integration is disabled (`-shellcheck=`) for now: it
|
||||||
|
# reports 4 pre-existing findings in the deploy/CI run-steps (SC2044 find-in-for
|
||||||
|
# loops, SC2046/SC2086 quoting, one of which is intentional word-splitting in the
|
||||||
|
# SAM deploy step). Those deserve a separate, tested cleanup rather than being
|
||||||
|
# bundled into the gate that unblocks the repo. Re-enable shellcheck once fixed.
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
ci:
|
||||||
|
name: ci / ci
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v6
|
||||||
|
|
||||||
|
- name: Install actionlint
|
||||||
|
env:
|
||||||
|
ACTIONLINT_VERSION: 1.7.12
|
||||||
|
ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
|
||||||
|
run: |
|
||||||
|
curl -fsSL -o actionlint.tar.gz \
|
||||||
|
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
|
||||||
|
echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c -
|
||||||
|
tar -xzf actionlint.tar.gz actionlint
|
||||||
|
shell: bash
|
||||||
|
|
||||||
|
- name: Lint workflows
|
||||||
|
run: ./actionlint -color -shellcheck=
|
||||||
|
shell: bash
|
||||||
2
.github/workflows/compliance-audit.yaml
vendored
2
.github/workflows/compliance-audit.yaml
vendored
|
|
@ -76,7 +76,7 @@ jobs:
|
||||||
|
|
||||||
- name: Run compliance audit
|
- name: Run compliance audit
|
||||||
id: audit
|
id: audit
|
||||||
uses: anthropics/claude-code-action@0f97b95b6536c26e5f6bd90faec370d41695beca # v1
|
uses: anthropics/claude-code-action@4d7e1f0cd85743fdc93b1c8040ab54395da024e2 # v1
|
||||||
with:
|
with:
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
prompt: |
|
prompt: |
|
||||||
|
|
|
||||||
25
.github/workflows/labeler.yaml
vendored
Normal file
25
.github/workflows/labeler.yaml
vendored
Normal file
|
|
@ -0,0 +1,25 @@
|
||||||
|
name: labeler
|
||||||
|
|
||||||
|
# Thin caller that runs the org-wide reusable PR labeler (callable-labeler.yaml)
|
||||||
|
# on THIS repo's own pull requests. The .github repo is the single source of truth
|
||||||
|
# for the reusable workflows, but — like any consumer repo — it must invoke them
|
||||||
|
# via a caller to use them on itself; without this, the labeler never runs on
|
||||||
|
# .github's own PRs (the reusable is `workflow_call`-only).
|
||||||
|
#
|
||||||
|
# Permissions are load-bearing: callers MUST grant all three below. Reusable-
|
||||||
|
# workflow permissions can only be downgraded from the caller, so omitting one
|
||||||
|
# (e.g. issues:write) either fails to create labels or triggers a silent
|
||||||
|
# startup_failure. `pull_request` (NOT pull_request_target) is correct here — the
|
||||||
|
# org takes no fork PRs, so the lower-privilege event is sufficient.
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
pull-requests: write
|
||||||
|
issues: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
label:
|
||||||
|
uses: ./.github/workflows/callable-labeler.yaml
|
||||||
Loading…
Add table
Reference in a new issue