diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 7604166..60c1150 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -19,11 +19,6 @@ name: ci # the check-run name IS the job name, so the aggregator is named literally # "ci-complete". Do not put the portion job names in a ruleset. # -# The trailing `ci` job (check-run name "ci / ci") is temporary. Until the org -# ruleset cutover moves this repo from "main branch protection" onto "CI -# complete", main still requires `ci / ci`; that job mirrors `ci-complete` so -# the legacy context stays satisfiable. Drop it after the cutover. -# # actionlint is pinned to a tagged release and installed by downloading the # release tarball and verifying its SHA256 — not `curl | bash` — to keep the # supply-chain surface auditable. Bump ACTIONLINT_VERSION + ACTIONLINT_SHA256 @@ -103,20 +98,3 @@ jobs: set -euo pipefail test "${ISOLATION_TESTS}" = success test "${ACTIONLINT}" = success - - # Temporary legacy context for main branch protection. `always()` plus the - # explicit result test matter: a skipped required check counts as passing, - # so this must run and fail whenever ci-complete does not succeed. - ci: - name: ci / ci - needs: ci-complete - if: always() && !cancelled() - runs-on: ubuntu-latest - timeout-minutes: 5 - steps: - - name: Mirror ci-complete - env: - CI_COMPLETE: ${{ needs.ci-complete.result }} - run: | - set -euo pipefail - test "${CI_COMPLETE}" = success diff --git a/README.md b/README.md index 04c25c5..aabc1e1 100644 --- a/README.md +++ b/README.md @@ -89,7 +89,7 @@ The formatter GitHub App is not on the main-branch bypass list. **`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs. -**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. A temporary `ci` job mirrors `ci-complete` as `ci / ci` until this repo's ruleset cutover lands; drop it afterwards. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted. +**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted. ### Workflow templates (`workflow-templates/`)