From 068e6a7c48d912276a296dbd9674b241cf0e0c09 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 29 Jul 2026 12:17:44 -0400 Subject: [PATCH] ci: emit the ci / ci status context required by the org ruleset The org main-branch ruleset requires the status context `ci / ci`. A job defined directly in a workflow emits only its job name, so this repo's CI published `ci` and could never satisfy that rule. The two-part context comes from a reusable-workflow call, named ` / `. Move the checks into a local reusable and leave ci.yaml as a thin caller, which is also the structural convention the org reusables follow. No org reusable fits a bash and workflow tooling repo, so the reusable lives here. --- .github/workflows/ci-runner-checks.yaml | 79 +++++++++++++++++++++++++ .github/workflows/ci.yaml | 53 ++--------------- README.md | 3 +- 3 files changed, 86 insertions(+), 49 deletions(-) create mode 100644 .github/workflows/ci-runner-checks.yaml diff --git a/.github/workflows/ci-runner-checks.yaml b/.github/workflows/ci-runner-checks.yaml new file mode 100644 index 0000000..db8a6db --- /dev/null +++ b/.github/workflows/ci-runner-checks.yaml @@ -0,0 +1,79 @@ +name: CI — Runner Checks + +# Reusable CI for this repository's own shell/workflow tooling. Kept as a +# reusable (rather than inlining the steps in ci.yaml) so the caller emits the +# two-part `ci / ci` status context the org "main branch protection" ruleset +# requires. None of the org reusables fit a bash + workflow tooling repo: +# ci-static validates HTML, ci-typescript-* and ci-python-* expect a package +# manifest, ci-dotnet expects a solution. This repo has none of those. + +on: + workflow_call: + inputs: + actionlint-version: + description: actionlint release to download + type: string + default: "1.7.12" + actionlint-sha256: + description: sha256 of the actionlint linux_amd64 tarball + type: string + default: "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8" + check-jsonschema-version: + description: pinned check-jsonschema version + type: string + default: "0.37.4" + +permissions: + contents: read + +jobs: + ci: + runs-on: ubuntu-latest + timeout-minutes: 15 + concurrency: + group: ci-runner-checks-${{ github.workflow }}-${{ github.job }}-${{ github.ref }} + cancel-in-progress: true + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: shellcheck all scripts + run: | + shopt -s nullglob + files=(scripts/*.sh tests/*.sh) + echo "checking: ${files[*]}" + shellcheck --external-sources --source-path=scripts "${files[@]}" + + - name: actionlint all workflows + env: + ACTIONLINT_VERSION: ${{ inputs.actionlint-version }} + ACTIONLINT_SHA256: ${{ inputs.actionlint-sha256 }} + run: | + curl -sSfL -o actionlint.tar.gz \ + "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" + echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c - + tar -xzf actionlint.tar.gz actionlint + ./actionlint -color + + - name: validate input schema + fixtures + env: + CHECK_JSONSCHEMA_VERSION: ${{ inputs.check-jsonschema-version }} + run: | + # Pinned: the same integrity bar the actionlint download above meets. + python3 -m pip install --quiet "check-jsonschema==${CHECK_JSONSCHEMA_VERSION}" + check-jsonschema --check-metaschema review/schemas/review-input.schema.json + for f in tests/fixtures/inputs/valid-*.json; do + check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" + done + for f in tests/fixtures/inputs/invalid-*.json; do + if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then + echo "expected $f to FAIL schema validation" >&2; exit 1 + fi + done + + - name: bash tests + run: | + ./tests/test-input-validation.sh + ./tests/test-output-validation.sh + ./tests/test-gate-integrity.sh diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 0b7bca8..50f33d6 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -1,9 +1,9 @@ name: ci -# Repo-local CI for the runner itself. No org reusable fits a bash/workflow -# tooling repo, so this thin workflow lints every script and workflow, validates -# the input schema, and runs the bash test suite. The job is named `ci` so the -# required status context is `ci / ci`, matching the org ruleset convention. +# Thin caller, matching the org convention. The job id `ci` calling a reusable +# whose job id is also `ci` produces the status context `ci / ci`, which is the +# check the org "main branch protection" ruleset requires. A job defined +# directly here would emit only `ci` and would never satisfy that rule. on: pull_request: @@ -14,47 +14,4 @@ permissions: jobs: ci: - runs-on: ubuntu-latest - timeout-minutes: 15 - concurrency: - group: ci-${{ github.ref }} - cancel-in-progress: true - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: shellcheck all scripts - run: | - shopt -s nullglob - files=(scripts/*.sh tests/*.sh) - echo "checking: ${files[*]}" - shellcheck --external-sources --source-path=scripts "${files[@]}" - - - name: actionlint all workflows - run: | - curl -sSfL -o actionlint.tar.gz \ - https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz - echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 actionlint.tar.gz" | sha256sum -c - - tar -xzf actionlint.tar.gz actionlint - ./actionlint -color - - - name: validate input schema + fixtures - run: | - # Pinned: the same integrity bar the actionlint download above meets. - python3 -m pip install --quiet 'check-jsonschema==0.37.4' - check-jsonschema --check-metaschema review/schemas/review-input.schema.json - for f in tests/fixtures/inputs/valid-*.json; do - check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" - done - for f in tests/fixtures/inputs/invalid-*.json; do - if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then - echo "expected $f to FAIL schema validation" >&2; exit 1 - fi - done - - - name: bash tests - run: | - ./tests/test-input-validation.sh - ./tests/test-output-validation.sh - ./tests/test-gate-integrity.sh + uses: ./.github/workflows/ci-runner-checks.yaml diff --git a/README.md b/README.md index 0bd4bb4..bc0c41d 100644 --- a/README.md +++ b/README.md @@ -40,7 +40,8 @@ these NOT_RUN — reviews cannot claim them. | --- | --- | | `skills/pr-review/` | Coordinating skill + frontend/backend checklists + output contract | | `.github/workflows/review-pr.yml` | The review workflow (workflow_dispatch) | -| `.github/workflows/ci.yaml` | Repo CI: shellcheck, actionlint, schema check, bash tests | +| `.github/workflows/ci.yaml` | Repo CI caller (emits the required `ci / ci` context) | +| `.github/workflows/ci-runner-checks.yaml` | Reusable CI: shellcheck, actionlint, schema check, bash tests | | `scripts/` | Orchestration scripts (see headers in each) | | `review/runner-config.yml` | Source-of-truth config record (mirrored by the workflow env) | | `review/schemas/` | Input contract schema |