Skip to content

ci: harden GitHub-hosted checks and publishing - #12

Merged
biw merged 6 commits into
mainfrom
ci/github-hosted-pull-requests
Oct 5, 2026
Merged

biw merged 6 commits into
mainfrom
ci/github-hosted-pull-requests

Conversation

@biw

@biw biw commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Run pull-request checks directly on GitHub-hosted ubuntu-latest with pull_request, read-only repository permissions, and credential-free checkout. The tests and Docker build use public dependencies and local services, so remove the obsolete Cloudflare approval jobs. CI and publishing use Node 26, with a matching CI dependency cache key. Publishing stays restricted to successful pushes on main after both CI jobs and the runner image check succeed.

  • Skip the network-based agent skills installer in CI, including the publishing job, while preserving local installation and its exit status.
  • Pin third-party actions to verified upstream commit SHAs and add weekly Dependabot updates for those pins.
  • Add maintainer ownership for workflow, publishing, dependency, and Docker image inputs.
  • Run CI and the Docker check on ubuntu-latest and replace the bundled Corepack dependency in CI with a SHA-pinned pnpm setup action that uses the version in package.json.
  • Replace the local publishing implementation with calls to biw/npm-trusted-publish-workflows@v1, currently pointing to the released v1.1.0, so future v1 releases are picked up across repositories. The shared workflows use Node 26 on ubuntu-latest, support prepublishOnly, reject stale or mismatched tested commits, and tag the exact published revision. Keep the existing local workflow names and pass the tested SHA explicitly.

Repository protection is already active: main requires a PR, with no mandatory reviewer or additional approval gate. A maintainer's merge is the approval to publish. The existing admin bypass is restricted to PR merges; direct pushes cannot use that bypass. Deletion and force-push protections are preserved.

Validation: on the latest head a448b19, both GitHub-hosted CI jobs passed all 303 tests across 30 files, formatting, lint, type checks, and package builds on Node 26 and ubuntu-latest, including all five installer regression tests. The Docker image is 1,249,803,889 bytes, below the 1,500,000,000-byte limit. Local workflow actionlint, formatting, and diff checks passed. The released shared publisher passed its 20 regression tests and package-manager bootstrap checks on Node 24 and 26. Publishing remains skipped for pull requests. Package version 1.0.10 is already on npm, so the merge should skip republishing; actual OIDC authentication in the shared publisher will be exercised on the next unpublished package version. The existing ci.yml caller identity is preserved and matches the published package's provenance.

This PR contains CI and publishing hardening and can be merged independently of the scheduler changes in #11.

@biw biw changed the title ci: run GitHub-hosted checks on pull requests ci: harden GitHub-hosted checks and publishing Oct 5, 2026
@biw
biw merged commit 25960b1 into main Oct 5, 2026
10 checks passed
@biw
biw deleted the ci/github-hosted-pull-requests branch October 5, 2026 23:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant