Skip to content

fix(ci): reject unexpected skipped jobs [HELM-815] - #28

Merged
peycheff-com merged 1 commit into
mainfrom
ci-skip-policy
Sep 27, 2026
Merged

peycheff-com merged 1 commit into
mainfrom
ci-skip-policy

Conversation

@peycheff-com

@peycheff-com peycheff-com commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Change

Close HELM-815's shared required-gate gap without changing workflow inputs, secrets or job names.

  • check must succeed.
  • dependency-scan may skip only outside pull_request and merge_group, matching its existing job condition.
  • Both required dependency names must be present. Additional jobs must succeed; a new skipped job receives no implicit allowance.
  • Empty event context fails closed. Failures and cancellations remain failures.

The gate remains inline because reusable workflows check out the caller repository. README now describes the exact policy.

Validation

The tests execute the actual inline shell, not a separate model of it: 96 combinations of six caller events and four results per dependency, plus missing dependencies, additional-job results and missing event context. Against the old gate, they produced 19 failing subcases because forbidden skips/missing jobs passed. Native make check passed: actionlint, shellcheck, and all 36 Python test methods (including the full event/result matrix). Diff whitespace validation passed.

WS-C independently reviewed the three changed files: no actionable findings. Its rerun passed all four gate test methods, including 96 combinations; raw unknown-check, unknown-scan, missing check.result and null extra-job payloads also refused. Report: output/helm-789-wsc-release-2026-09-27/platform-gate-review.md. The repository's self-CI calls these proposed local workflows and includes auto-tag/image dry runs.

Delivery

After native checks, complete hosted CI and adversarial review, merge and promote the documented moving-major v2 alias to the exact merge commit with authoritative readback and a HELM-815 operation record. No immutable version tag, deployment or secret is changed by this PR. Existing PR runs resolve their reusable workflow at run start; the new alias applies to subsequent runs.

@peycheff-com
peycheff-com marked this pull request as ready for review September 27, 2026 18:49
@peycheff-com
peycheff-com merged commit 0e5957e into main Sep 27, 2026
7 checks passed
@peycheff-com
peycheff-com deleted the ci-skip-policy branch September 27, 2026 18:55
@peycheff-com

Copy link
Copy Markdown
Contributor Author

HELM-815 shared CI promotion receipt

Operation: promote the documented moving-major v2 reusable workflow alias.
Actor: peycheff-com.
Target: Mindburn-Labs/platform-actions, merge commit 0e5957e81a5bcdd5cd13cb53ab5e759984c2bbc0 from #28.
Before: annotated tag object e0eee8227f849ea8c7078f70d9ba7fb945e2c9cd, peeled commit 2ecbf8bb1babcdcae19052181f12ee97aea71ea6. No GitHub Release named v2. Only the reviewed gate change and runbook documentation lie between the old and new target.
Validation: native make check passed all 36 tests, actionlint and shellcheck; 96 event/result cases plus missing/extra job checks; 19 failing negative subcases on the old gate. WS-C independent review found no actionable issues. PR CI 36342018287 and exact merged-source CI 36342424527 passed, including auto-tag and image dry runs. Main demonstrated the intended check-success / scan-skipped push behavior.
Command: git tag -fa v2 -m 'v2: reject unexpected skipped CI jobs [HELM-815]' 0e5957e81a5bcdd5cd13cb53ab5e759984c2bbc0, then git push --force-with-lease=refs/tags/v2:e0eee8227f849ea8c7078f70d9ba7fb945e2c9cd origin refs/tags/v2.
Readback: API and git remote agree on new tag object a468dd0da679511cf7eac5cd06eba5b26bec692f, peeled commit 0e5957e81a5bcdd5cd13cb53ab5e759984c2bbc0. The workflow resolved through v2 has reviewed blob 57f5b084c621e68c9a6b351087f783a908c53e69.
Audit: merge event 6e8Byrl1q6FyIkiRh9FGAQ; completed merged-source workflow IJRL3lymebMsTUUrhW7qEg. A separate Git push audit query is retained locally; remote ref readback is the authoritative tag result.
Follow-up: HELM-815 still needs the CP pin guard to land via #529. Subsequent CI calls use the stricter v2; already-running workflow resolutions are unchanged. No immutable release version, deployed environment or credential was changed. Linear tools became unavailable during this turn, so this operation receipt is posted here and retained in the WS-B local report for later issue synchronization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant