mirror of
https://github.com/Sea-Haven-Industries/shoc-pr-review-runner.git
synced 2026-09-30 07:13:14 +00:00
ci: emit the ci / ci status context required by the org ruleset
The org main-branch ruleset requires the status context `ci / ci`. A job defined directly in a workflow emits only its job name, so this repo's CI published `ci` and could never satisfy that rule. The two-part context comes from a reusable-workflow call, named `<caller job> / <called job>`. Move the checks into a local reusable and leave ci.yaml as a thin caller, which is also the structural convention the org reusables follow. No org reusable fits a bash and workflow tooling repo, so the reusable lives here.
This commit is contained in:
parent
c3cd8f7765
commit
068e6a7c48
3 changed files with 86 additions and 49 deletions
79
.github/workflows/ci-runner-checks.yaml
vendored
Normal file
79
.github/workflows/ci-runner-checks.yaml
vendored
Normal file
|
|
@ -0,0 +1,79 @@
|
|||
name: CI — Runner Checks
|
||||
|
||||
# Reusable CI for this repository's own shell/workflow tooling. Kept as a
|
||||
# reusable (rather than inlining the steps in ci.yaml) so the caller emits the
|
||||
# two-part `ci / ci` status context the org "main branch protection" ruleset
|
||||
# requires. None of the org reusables fit a bash + workflow tooling repo:
|
||||
# ci-static validates HTML, ci-typescript-* and ci-python-* expect a package
|
||||
# manifest, ci-dotnet expects a solution. This repo has none of those.
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
actionlint-version:
|
||||
description: actionlint release to download
|
||||
type: string
|
||||
default: "1.7.12"
|
||||
actionlint-sha256:
|
||||
description: sha256 of the actionlint linux_amd64 tarball
|
||||
type: string
|
||||
default: "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8"
|
||||
check-jsonschema-version:
|
||||
description: pinned check-jsonschema version
|
||||
type: string
|
||||
default: "0.37.4"
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
ci:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
concurrency:
|
||||
group: ci-runner-checks-${{ github.workflow }}-${{ github.job }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: shellcheck all scripts
|
||||
run: |
|
||||
shopt -s nullglob
|
||||
files=(scripts/*.sh tests/*.sh)
|
||||
echo "checking: ${files[*]}"
|
||||
shellcheck --external-sources --source-path=scripts "${files[@]}"
|
||||
|
||||
- name: actionlint all workflows
|
||||
env:
|
||||
ACTIONLINT_VERSION: ${{ inputs.actionlint-version }}
|
||||
ACTIONLINT_SHA256: ${{ inputs.actionlint-sha256 }}
|
||||
run: |
|
||||
curl -sSfL -o actionlint.tar.gz \
|
||||
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
|
||||
echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c -
|
||||
tar -xzf actionlint.tar.gz actionlint
|
||||
./actionlint -color
|
||||
|
||||
- name: validate input schema + fixtures
|
||||
env:
|
||||
CHECK_JSONSCHEMA_VERSION: ${{ inputs.check-jsonschema-version }}
|
||||
run: |
|
||||
# Pinned: the same integrity bar the actionlint download above meets.
|
||||
python3 -m pip install --quiet "check-jsonschema==${CHECK_JSONSCHEMA_VERSION}"
|
||||
check-jsonschema --check-metaschema review/schemas/review-input.schema.json
|
||||
for f in tests/fixtures/inputs/valid-*.json; do
|
||||
check-jsonschema --schemafile review/schemas/review-input.schema.json "$f"
|
||||
done
|
||||
for f in tests/fixtures/inputs/invalid-*.json; do
|
||||
if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then
|
||||
echo "expected $f to FAIL schema validation" >&2; exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
- name: bash tests
|
||||
run: |
|
||||
./tests/test-input-validation.sh
|
||||
./tests/test-output-validation.sh
|
||||
./tests/test-gate-integrity.sh
|
||||
53
.github/workflows/ci.yaml
vendored
53
.github/workflows/ci.yaml
vendored
|
|
@ -1,9 +1,9 @@
|
|||
name: ci
|
||||
|
||||
# Repo-local CI for the runner itself. No org reusable fits a bash/workflow
|
||||
# tooling repo, so this thin workflow lints every script and workflow, validates
|
||||
# the input schema, and runs the bash test suite. The job is named `ci` so the
|
||||
# required status context is `ci / ci`, matching the org ruleset convention.
|
||||
# Thin caller, matching the org convention. The job id `ci` calling a reusable
|
||||
# whose job id is also `ci` produces the status context `ci / ci`, which is the
|
||||
# check the org "main branch protection" ruleset requires. A job defined
|
||||
# directly here would emit only `ci` and would never satisfy that rule.
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
|
|
@ -14,47 +14,4 @@ permissions:
|
|||
|
||||
jobs:
|
||||
ci:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
concurrency:
|
||||
group: ci-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: shellcheck all scripts
|
||||
run: |
|
||||
shopt -s nullglob
|
||||
files=(scripts/*.sh tests/*.sh)
|
||||
echo "checking: ${files[*]}"
|
||||
shellcheck --external-sources --source-path=scripts "${files[@]}"
|
||||
|
||||
- name: actionlint all workflows
|
||||
run: |
|
||||
curl -sSfL -o actionlint.tar.gz \
|
||||
https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz
|
||||
echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 actionlint.tar.gz" | sha256sum -c -
|
||||
tar -xzf actionlint.tar.gz actionlint
|
||||
./actionlint -color
|
||||
|
||||
- name: validate input schema + fixtures
|
||||
run: |
|
||||
# Pinned: the same integrity bar the actionlint download above meets.
|
||||
python3 -m pip install --quiet 'check-jsonschema==0.37.4'
|
||||
check-jsonschema --check-metaschema review/schemas/review-input.schema.json
|
||||
for f in tests/fixtures/inputs/valid-*.json; do
|
||||
check-jsonschema --schemafile review/schemas/review-input.schema.json "$f"
|
||||
done
|
||||
for f in tests/fixtures/inputs/invalid-*.json; do
|
||||
if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then
|
||||
echo "expected $f to FAIL schema validation" >&2; exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
- name: bash tests
|
||||
run: |
|
||||
./tests/test-input-validation.sh
|
||||
./tests/test-output-validation.sh
|
||||
./tests/test-gate-integrity.sh
|
||||
uses: ./.github/workflows/ci-runner-checks.yaml
|
||||
|
|
|
|||
|
|
@ -40,7 +40,8 @@ these NOT_RUN — reviews cannot claim them.
|
|||
| --- | --- |
|
||||
| `skills/pr-review/` | Coordinating skill + frontend/backend checklists + output contract |
|
||||
| `.github/workflows/review-pr.yml` | The review workflow (workflow_dispatch) |
|
||||
| `.github/workflows/ci.yaml` | Repo CI: shellcheck, actionlint, schema check, bash tests |
|
||||
| `.github/workflows/ci.yaml` | Repo CI caller (emits the required `ci / ci` context) |
|
||||
| `.github/workflows/ci-runner-checks.yaml` | Reusable CI: shellcheck, actionlint, schema check, bash tests |
|
||||
| `scripts/` | Orchestration scripts (see headers in each) |
|
||||
| `review/runner-config.yml` | Source-of-truth config record (mirrored by the workflow env) |
|
||||
| `review/schemas/` | Input contract schema |
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue