Repository navigation
ci: GitHub App authentication and path-filtered jobs - #106
Merged
Merged
Conversation
Release PRs opened with the App token run CI, and Trivy and the CLI/Docker tests get the App's higher API rate limit. The tests fall back to GITHUB_TOKEN when the App secrets are unavailable.
Classify changed files with the shared classify-changes workflow and run tests, builds and scans only when a non-prose file changed. Lint always runs since it also checks markdown. Release PRs only bump the version in package.json besides the changelog and manifest, so package.json counts as prose on release-please branches.
Replace the inline all-jobs-passed script with check-jobs, lint pull request commits since they land on main as is with rebase merges, and scan the history for leaked secrets with gitleaks.
Contributor
|
🤖 Hey ! The security scan report for the current pull request is available in the GitHub Security Tab. |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Contributor
|
🤖 Hey ! ✅ Gitleaks found no leaked secrets in the git history. The secret scan report for the current pull request is available in the GitHub Security Tab. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
GitHub App authentication
release(CD): release PRs opened with the App token now trigger CI.scan-vuln: Trivy gets the App's higher GitHub API rate limit (5,000 vs 1,000 requests/hour).tests-cli/tests-docker: declare theAPP_CLIENT_ID/APP_PRIVATE_KEYsecrets and mint a read-only token (contents: read,metadata: read) for the GitHub API calls docpress makes. They fall back toGITHUB_TOKENwhen the secrets are unavailable (e.g. fork pull requests).build-dockeris left as is: it only uses the App to inject a build secret, which the Dockerfile does not need.lint-js,test-vitest,release-npmand the cache/image cleanup workflows take no App credentials.Skip code jobs on docs-only pull requests
path-filterjob using the sharedclassify-changes.ymlworkflow.tests-unit,tests-cliandbuild-dockerrun only when a non-prose file changed;tests-docker,scan-vulnandcode-scanfollow through their dependencies.lintalways runs, since ESLint also checks markdown.docs/*,*.md,LICENSE,NOTICE,.release-please-manifest.json), pluspackage.jsononrelease-please--*branches only: release PRs just bump its version, while any otherpackage.jsonchange still runs the full suite.all-jobs-passedalso waits onpath-filter, so a classification failure fails the required check.workflow_dispatch), every job runs.Shared workflows
all-jobs-passednow uses the sharedcheck-jobs.ymlinstead of an inline script (skipped jobs still count as a pass, as the path filter needs).lint-commits: lints pull request commits against.commitlintrc.json. Merges are rebase-only, so every commit lands on main as is and feeds release-please.scan-secrets: gitleaks scan of the history, blocking, with SARIF uploaded to the Security tab (a local run over all 247 commits found no leaks).Notes
The required check is renamed from
Check jobs statustoCheck jobs status / Required jobs(reusable workflow checks are prefixed with the calling job name). Themainruleset must be updated accordingly, otherwise every pull request waits on a check that no longer reports.actionlint 1.7.12 flags
client-idonactions/create-github-app-token@v3; that input is valid (it replaced the deprecatedapp-id) and is what the shared workflows use.