ci: emit the ci / ci status context required by the org ruleset

The org main-branch ruleset requires the status context `ci / ci`. A job
defined directly in a workflow emits only its job name, so this repo's CI
published `ci` and could never satisfy that rule. The two-part context comes
from a reusable-workflow call, named `<caller job> / <called job>`.

Move the checks into a local reusable and leave ci.yaml as a thin caller, which
is also the structural convention the org reusables follow. No org reusable
fits a bash and workflow tooling repo, so the reusable lives here.
This commit is contained in:
Adam Moussa 2026-07-29 12:17:44 -04:00
parent c3cd8f7765
commit 068e6a7c48
No known key found for this signature in database
3 changed files with 86 additions and 49 deletions

79
.github/workflows/ci-runner-checks.yaml vendored Normal file
View file

@ -0,0 +1,79 @@
name: CI — Runner Checks
# Reusable CI for this repository's own shell/workflow tooling. Kept as a
# reusable (rather than inlining the steps in ci.yaml) so the caller emits the
# two-part `ci / ci` status context the org "main branch protection" ruleset
# requires. None of the org reusables fit a bash + workflow tooling repo:
# ci-static validates HTML, ci-typescript-* and ci-python-* expect a package
# manifest, ci-dotnet expects a solution. This repo has none of those.
on:
workflow_call:
inputs:
actionlint-version:
description: actionlint release to download
type: string
default: "1.7.12"
actionlint-sha256:
description: sha256 of the actionlint linux_amd64 tarball
type: string
default: "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8"
check-jsonschema-version:
description: pinned check-jsonschema version
type: string
default: "0.37.4"
permissions:
contents: read
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 15
concurrency:
group: ci-runner-checks-${{ github.workflow }}-${{ github.job }}-${{ github.ref }}
cancel-in-progress: true
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: shellcheck all scripts
run: |
shopt -s nullglob
files=(scripts/*.sh tests/*.sh)
echo "checking: ${files[*]}"
shellcheck --external-sources --source-path=scripts "${files[@]}"
- name: actionlint all workflows
env:
ACTIONLINT_VERSION: ${{ inputs.actionlint-version }}
ACTIONLINT_SHA256: ${{ inputs.actionlint-sha256 }}
run: |
curl -sSfL -o actionlint.tar.gz \
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c -
tar -xzf actionlint.tar.gz actionlint
./actionlint -color
- name: validate input schema + fixtures
env:
CHECK_JSONSCHEMA_VERSION: ${{ inputs.check-jsonschema-version }}
run: |
# Pinned: the same integrity bar the actionlint download above meets.
python3 -m pip install --quiet "check-jsonschema==${CHECK_JSONSCHEMA_VERSION}"
check-jsonschema --check-metaschema review/schemas/review-input.schema.json
for f in tests/fixtures/inputs/valid-*.json; do
check-jsonschema --schemafile review/schemas/review-input.schema.json "$f"
done
for f in tests/fixtures/inputs/invalid-*.json; do
if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then
echo "expected $f to FAIL schema validation" >&2; exit 1
fi
done
- name: bash tests
run: |
./tests/test-input-validation.sh
./tests/test-output-validation.sh
./tests/test-gate-integrity.sh

View file

@ -1,9 +1,9 @@
name: ci
# Repo-local CI for the runner itself. No org reusable fits a bash/workflow
# tooling repo, so this thin workflow lints every script and workflow, validates
# the input schema, and runs the bash test suite. The job is named `ci` so the
# required status context is `ci / ci`, matching the org ruleset convention.
# Thin caller, matching the org convention. The job id `ci` calling a reusable
# whose job id is also `ci` produces the status context `ci / ci`, which is the
# check the org "main branch protection" ruleset requires. A job defined
# directly here would emit only `ci` and would never satisfy that rule.
on:
pull_request:
@ -14,47 +14,4 @@ permissions:
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 15
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: shellcheck all scripts
run: |
shopt -s nullglob
files=(scripts/*.sh tests/*.sh)
echo "checking: ${files[*]}"
shellcheck --external-sources --source-path=scripts "${files[@]}"
- name: actionlint all workflows
run: |
curl -sSfL -o actionlint.tar.gz \
https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz
echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 actionlint.tar.gz" | sha256sum -c -
tar -xzf actionlint.tar.gz actionlint
./actionlint -color
- name: validate input schema + fixtures
run: |
# Pinned: the same integrity bar the actionlint download above meets.
python3 -m pip install --quiet 'check-jsonschema==0.37.4'
check-jsonschema --check-metaschema review/schemas/review-input.schema.json
for f in tests/fixtures/inputs/valid-*.json; do
check-jsonschema --schemafile review/schemas/review-input.schema.json "$f"
done
for f in tests/fixtures/inputs/invalid-*.json; do
if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then
echo "expected $f to FAIL schema validation" >&2; exit 1
fi
done
- name: bash tests
run: |
./tests/test-input-validation.sh
./tests/test-output-validation.sh
./tests/test-gate-integrity.sh
uses: ./.github/workflows/ci-runner-checks.yaml

View file

@ -40,7 +40,8 @@ these NOT_RUN — reviews cannot claim them.
| --- | --- |
| `skills/pr-review/` | Coordinating skill + frontend/backend checklists + output contract |
| `.github/workflows/review-pr.yml` | The review workflow (workflow_dispatch) |
| `.github/workflows/ci.yaml` | Repo CI: shellcheck, actionlint, schema check, bash tests |
| `.github/workflows/ci.yaml` | Repo CI caller (emits the required `ci / ci` context) |
| `.github/workflows/ci-runner-checks.yaml` | Reusable CI: shellcheck, actionlint, schema check, bash tests |
| `scripts/` | Orchestration scripts (see headers in each) |
| `review/runner-config.yml` | Source-of-truth config record (mirrored by the workflow env) |
| `review/schemas/` | Input contract schema |