The inline ci/ci aggregator green-lit the org-required check when a needed job was SKIPPED (result 'skipped' is neither 'failure' nor 'cancelled'). Treat 'skipped' as a failure so a conditionally-skipped required job can no longer pass the required check without running. Contained inline fix; the audit's shared callable-ci-aggregate.yaml (Stub 4) is deferred as it needs a new org-wide reusable workflow.
29 lines
1.1 KiB
YAML
29 lines
1.1 KiB
YAML
name: CI
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
python:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
|
with:
|
|
source-dirs: "src"
|
|
run-sam-validate: false
|
|
typescript:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
|
with:
|
|
run-cdk-synth: false
|
|
# Aggregator producing the org-required "ci / ci" status context.
|
|
# Caller jobs here have distinct names (python, typescript), so the
|
|
# org ruleset's required check would otherwise never report.
|
|
ci:
|
|
name: ci / ci
|
|
needs: [python, typescript]
|
|
if: always()
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: All CI jobs passed
|
|
run: |
|
|
# A skipped needed job must NOT green-light the required "ci / ci"
|
|
# context, so treat 'skipped' as a failure alongside failure/cancelled.
|
|
[ "${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') || contains(needs.*.result, 'skipped') }}" = "false" ]
|