afterhours-shift-manager/.github/workflows
Adam Moussa ed32541331 Move release/announce into Deploy workflow to clear CodeQL
The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.

Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:38:53 -04:00
..
changelog-guard.yml Add changelog-driven releases and App Home tab 2026-06-11 19:15:20 -04:00
ci.yaml Add pytest suite and wire it into CI (#85) (#86) 2026-06-01 19:07:08 -04:00
dependency-review.yml Add dependency-review caller workflow (#97) 2026-06-05 12:26:41 -04:00
deploy.yaml Move release/announce into Deploy workflow to clear CodeQL 2026-06-11 19:38:53 -04:00
labeler.yml Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#106) 2026-06-11 14:13:35 -04:00