From 336f4f0988c8fbde0c5cdd4fe423cdbee5fa02f1 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Fri, 9 Oct 2026 22:20:11 +0000 Subject: [PATCH] chore(sync): synced file(s) with cplieger/ci --- .github/workflows/ci.yaml | 21 ++++++++------------- .github/workflows/codeql.yml | 2 +- .github/workflows/release.yaml | 13 +++---------- .github/workflows/security.yml | 2 +- .golangci.yaml | 6 +++--- cliff.toml | 3 +-- 6 files changed, 17 insertions(+), 30 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index f20139e..8646438 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -1,16 +1,7 @@ # Synced from cplieger/ci/.github/workflow-templates/ci.yml — DO NOT EDIT. -# Single CI template for all releaseable repos. The central ci.yaml reusable -# workflow auto-detects repo surfaces (go.mod / jsr.json / Dockerfile / nested -# web frontend) and dispatches to the appropriate reusable workflow. Hybrid -# repos (Go + TS web frontend) run multiple jobs in parallel automatically — -# no per-repo configuration needed. -# -# No paths-ignore: the required status check (ci / validate) can never be -# satisfied if the workflow is skipped by a path filter — GitHub leaves the -# check pending forever, permanently blocking docs-only PRs. The workflow -# therefore always runs; the central ci.yaml gates the heavy language jobs on a -# real code change (so docs-only pushes run only detect + markdown + validate) -# and always runs the markdown lint. +# No paths-ignore: a workflow skipped by a path filter leaves the required +# ci / validate pending forever, so the meta ci.yaml gates its heavy jobs on a +# real code change instead. name: CI # Both branches stay listed: a repo that has not adopted a dev branch keeps @@ -35,4 +26,8 @@ concurrency: jobs: ci: - uses: cplieger/ci/.github/workflows/ci.yaml@f0229da815e0820c85a679dea8158cf2bd414925 # v3 + # The dead-code check uploads its findings to code scanning. + permissions: + contents: read + security-events: write + uses: cplieger/ci/.github/workflows/ci.yaml@c5c2a1ca2199a2eb407227df3b56a837b99cc736 # v3 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 8d8ccc0..bb94860 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -25,4 +25,4 @@ jobs: security-events: write contents: read actions: read - uses: cplieger/ci/.github/workflows/codeql.yaml@f0229da815e0820c85a679dea8158cf2bd414925 # v3 + uses: cplieger/ci/.github/workflows/codeql.yaml@c5c2a1ca2199a2eb407227df3b56a837b99cc736 # v3 diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index ec9ec91..d29e120 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -12,15 +12,8 @@ on: branches: [main, dev] workflow_dispatch: inputs: - # Read by the v2 pipeline's no-change gate through github.event.inputs - # (deliberately not forwarded via `with:`); the scheduled staleness - # rebuild dispatches with it while a repo's default branch is main. - skip_if_unchanged: - description: "Skip publishing when the rebuilt image is package-identical to :latest (used by the scheduled staleness rebuild)." - type: boolean - default: false - # Read by the two-branch pipeline through github.event.inputs, never - # `with:`, which a v2 pin does not declare. A stable run's dev barrier + # Read by the release pipeline through github.event.inputs, so this + # caller forwards nothing through `with:`. A stable run's dev barrier # dispatches `renumber` on dev; a person never needs to. mode: description: "'renumber' re-tags dev's newest builds under fresh pre-release versions; 'normal' otherwise." @@ -59,7 +52,7 @@ jobs: id-token: write attestations: write security-events: write - uses: cplieger/ci/.github/workflows/release.yaml@f0229da815e0820c85a679dea8158cf2bd414925 # v3 + uses: cplieger/ci/.github/workflows/release.yaml@c5c2a1ca2199a2eb407227df3b56a837b99cc736 # v3 # Forward only the two Docker Hub publish credentials the reusable pipeline # actually declares and consumes, rather than `secrets: inherit` (which # exposes every repo secret to the reusable-workflow trust boundary). Both diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 1f9c7ee..d36a9c5 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -28,4 +28,4 @@ jobs: permissions: contents: read security-events: write - uses: cplieger/ci/.github/workflows/security-scan.yaml@f0229da815e0820c85a679dea8158cf2bd414925 # v3 + uses: cplieger/ci/.github/workflows/security-scan.yaml@c5c2a1ca2199a2eb407227df3b56a837b99cc736 # v3 diff --git a/.golangci.yaml b/.golangci.yaml index 7b8d56b..2218a98 100644 --- a/.golangci.yaml +++ b/.golangci.yaml @@ -8,9 +8,9 @@ run: linters: default: standard - # unused, ineffassign and wastedassign are off: go-ci's deadset step reports - # the same findings (DS1002, DS1003, DS1807) and gates on them in every Go - # module. + # unused, ineffassign and wastedassign are off: the deadset check + # (deadset-ci.yaml) reports the same findings (DS1002, DS1003, DS1807) and + # gates on them in every Go module. disable: - unused - ineffassign diff --git a/cliff.toml b/cliff.toml index da041eb..deec1a6 100644 --- a/cliff.toml +++ b/cliff.toml @@ -137,8 +137,7 @@ exclude_paths = [ "**/deadset.json", "**/deadset-ignore.json", "**/deadset-edges.json", - # knip's configs, and the retired .punused-ignore repos carry until they delete it. - "**/.punused-ignore", + # knip's configs. "**/knip.json", "**/knip.jsonc", "**/.knip.json",