Skip to content

ci: GitHub App authentication and path-filtered jobs - #106

Merged
this-is-tobi merged 3 commits into
mainfrom
ci/github-app-and-path-filter
Sep 30, 2026
Merged

this-is-tobi merged 3 commits into
mainfrom
ci/github-app-and-path-filter

Conversation

@this-is-tobi

@this-is-tobi this-is-tobi commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

GitHub App authentication

  • release (CD): release PRs opened with the App token now trigger CI.
  • scan-vuln: Trivy gets the App's higher GitHub API rate limit (5,000 vs 1,000 requests/hour).
  • tests-cli / tests-docker: declare the APP_CLIENT_ID / APP_PRIVATE_KEY secrets and mint a read-only token (contents: read, metadata: read) for the GitHub API calls docpress makes. They fall back to GITHUB_TOKEN when the secrets are unavailable (e.g. fork pull requests).

build-docker is left as is: it only uses the App to inject a build secret, which the Dockerfile does not need. lint-js, test-vitest, release-npm and the cache/image cleanup workflows take no App credentials.

Skip code jobs on docs-only pull requests

  • New path-filter job using the shared classify-changes.yml workflow.
  • tests-unit, tests-cli and build-docker run only when a non-prose file changed; tests-docker, scan-vuln and code-scan follow through their dependencies.
  • lint always runs, since ESLint also checks markdown.
  • Prose patterns are the shared defaults (docs/*, *.md, LICENSE, NOTICE, .release-please-manifest.json), plus package.json on release-please--* branches only: release PRs just bump its version, while any other package.json change still runs the full suite.
  • all-jobs-passed also waits on path-filter, so a classification failure fails the required check.
  • Outside a pull request (workflow_dispatch), every job runs.

Shared workflows

  • all-jobs-passed now uses the shared check-jobs.yml instead of an inline script (skipped jobs still count as a pass, as the path filter needs).
  • lint-commits: lints pull request commits against .commitlintrc.json. Merges are rebase-only, so every commit lands on main as is and feeds release-please.
  • scan-secrets: gitleaks scan of the history, blocking, with SARIF uploaded to the Security tab (a local run over all 247 commits found no leaks).

Notes

  • The required check is renamed from Check jobs status to Check jobs status / Required jobs (reusable workflow checks are prefixed with the calling job name). The main ruleset must be updated accordingly, otherwise every pull request waits on a check that no longer reports.

  • actionlint 1.7.12 flags client-id on actions/create-github-app-token@v3; that input is valid (it replaced the deprecated app-id) and is what the shared workflows use.

Release PRs opened with the App token run CI, and Trivy and the CLI/Docker tests get
the App's higher API rate limit. The tests fall back to GITHUB_TOKEN when the App
secrets are unavailable.
Classify changed files with the shared classify-changes workflow and run tests,
builds and scans only when a non-prose file changed. Lint always runs since it also
checks markdown. Release PRs only bump the version in package.json besides the
changelog and manifest, so package.json counts as prose on release-please branches.
Replace the inline all-jobs-passed script with check-jobs, lint pull request commits
since they land on main as is with rebase merges, and scan the history for leaked
secrets with gitleaks.
@github-actions

Copy link
Copy Markdown
Contributor

🤖 Hey !

The security scan report for the current pull request is available in the GitHub Security Tab.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

Copy link
Copy Markdown
Contributor

🤖 Hey !

✅ Gitleaks found no leaked secrets in the git history. The secret scan report for the current pull request is available in the GitHub Security Tab.

@this-is-tobi
this-is-tobi merged commit cb7f0b7 into main Sep 30, 2026
28 checks passed
@this-is-tobi
this-is-tobi deleted the ci/github-app-and-path-filter branch September 30, 2026 19:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants