From a54b9dcd4bddd73fd36e500445f154121c8de0ef Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?M=C4=81ris=20Pop=C4=93ns?= Date: Thu, 24 Sep 2026 10:59:51 +0000 Subject: [PATCH] chore(ci): trim workflow comments Keep only the non-obvious why; drop change history, restated code and long explanations. --- .github/dependabot.yml | 4 ---- .github/workflows/auto-merge.yml | 19 +++++-------------- .github/workflows/build.yml | 10 +++------- .github/workflows/release-please.yml | 5 +---- .github/workflows/security.yml | 6 +----- .github/workflows/validate.yml | 22 +++++----------------- .github/zizmor.yml | 9 ++------- 7 files changed, 17 insertions(+), 58 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 0366f0e..92980fa 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -15,8 +15,6 @@ updates: prefix: "fix" include: "scope" - # Base image bumps (golang:1.27-trixie builder, distroless/static-debian13 - # runtime). - package-ecosystem: "docker" cooldown: default-days: 7 @@ -31,8 +29,6 @@ updates: prefix: "fix" include: "scope" - # Grouped into a single PR so related action bumps land together rather than - # as a stream of separate PRs. Auto-merge handles them once CI passes. - package-ecosystem: "github-actions" cooldown: default-days: 7 diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 5576e2d..649bd08 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -7,16 +7,12 @@ on: jobs: auto-merge: - # The reusable workflow cannot grant itself more than the caller has, and - # the org default for GITHUB_TOKEN is read-only — so declare it here. + # The org default token is read-only. permissions: contents: write pull-requests: write - # Only the conclusion is checked, not workflow_run.event: a same-repo - # branch (which is how Dependabot pushes) triggers CI as 'push', not - # 'pull_request', so gating on the event silently skipped every run. The - # reusable workflow looks up the PR and enforces the author allow-list, - # which is the actual safety gate; a run with no open PR just no-ops. + # Not gated on workflow_run.event: Dependabot branches run CI as 'push'. + # The reusable workflow's author check is the real gate. if: >- github.event.workflow_run.conclusion == 'success' && (github.event.workflow_run.actor.login == 'dependabot[bot]' || @@ -25,14 +21,9 @@ jobs: with: # release-please's own PR; patch bumps auto-merge, minor/major don't. patch-only-authors: '["dnb-robot[bot]"]' - # GITHUB_TOKEN-authored merges don't trigger further workflow runs, which - # would leave a release-please release stuck (manifest/changelog bumped, - # no tag/release/images ever built) — see drumandbytes/reusable-actions#16. - # This merges with the dnb-robot app token instead, so the merge properly - # cascades into another Release Please run that actually finishes the release. + # A GITHUB_TOKEN merge triggers no workflows, so the release would never + # be cut (reusable-actions#16). use-app-token-for-merge: true - # Only the two secrets the called workflow uses, rather than `inherit` - # handing it every repo and org secret. secrets: DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }} AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }} diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 8d3fbd6..73bf8a0 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -8,11 +8,8 @@ on: - '**.md' - 'LICENSE' - '.gitignore' - # CI-config-only changes (Dependabot config, the auto-merge/validate - # workflows themselves) don't touch the image - no need for a full - # multi-arch build+push on every one of them. build.yml is explicitly - # re-included: a change to the workflow that actually builds and - # pushes the image should still be exercised for real, not skipped. + # CI-config-only changes skip the build; this file is re-included so edits + # to it still run. - '.github/**' - '!.github/workflows/build.yml' workflow_dispatch: @@ -61,8 +58,7 @@ jobs: tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} - # Signed SLSA build provenance for the pushed image, stored next to it - # in GHCR as an OCI referrer. Verify with: + # SLSA provenance, stored next to the image in GHCR. Verify with: # gh attestation verify oci://ghcr.io/drumandbytes/github-actions-runner-exporter:latest --owner drumandbytes - uses: actions/attest-build-provenance@v4.2.2 with: diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 022c8c2..b0c9e84 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -1,7 +1,6 @@ name: Release Please -# Merging the release PR tags vX.Y.Z, which build.yml already builds and -# pushes as a semver-tagged image. Immutable tags — no floating vN. +# The release tag triggers build.yml. Immutable tags, no floating vN. on: push: branches: [main] @@ -13,8 +12,6 @@ permissions: jobs: release-please: uses: drumandbytes/reusable-actions/.github/workflows/release-please.yml@v1 - # Only the two secrets the called workflow uses, rather than `inherit` - # handing it every repo and org secret. secrets: DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }} AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }} diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 1878afa..92fb21d 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -1,10 +1,6 @@ name: Security -# Kept out of the Validate workflow on purpose. Auto-merge gates on Validate's -# conclusion, so a scan there meant a vulnerability anywhere blocked every -# Dependabot merge, including ones that had nothing to do with it. Findings -# still fail this workflow; the weekly run catches advisories published -# against what's already on main. +# Separate from CI so a finding can't block auto-merge of an unrelated Dependabot fix. on: pull_request: branches: [main] diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 199404c..7bf5550 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -5,19 +5,13 @@ on: branches: [main] workflow_dispatch: -# No paths-ignore here on purpose: this workflow hosts required-checks-passed, -# which the org's branch ruleset requires by name on every PR. A path filter -# on the workflow trigger means GitHub never even starts the run for an -# excluded diff (e.g. a docs-only PR) -- not "skipped", just never reported -- -# so the ruleset's required check sits at "Expected" forever and the PR can't -# merge. Filter what runs inside jobs (paths-filter, changed-files, etc.) if -# needed, never the trigger. +# No paths-ignore: a filtered-out run never reports required-checks-passed, +# which the ruleset requires, so the PR could never merge. concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true -# Read-only token; no job here writes to the repo or reads other scopes. permissions: contents: read @@ -25,8 +19,7 @@ jobs: lint: uses: drumandbytes/reusable-actions/.github/workflows/go-ci.yml@v1 with: - # Explicit rather than read from go.mod: its `go 1.27.0` directive - # would install exactly 1.27.0, while "1.27" gets the latest 1.27.x. + # "1.27", not go.mod: `go 1.27.0` there would pin that exact patch. go-version: "1.27" dockerfile-path: Dockerfile @@ -44,9 +37,7 @@ jobs: load: true tags: github-actions-runner-exporter:smoke-test - # Fake credentials - never actually connects to the real GitHub API. - # This only proves the container starts cleanly, listens, and answers - # /healthz without crashing - not that it can reach a real org. + # Fake credentials: only proves the container starts and answers /healthz. - name: Container starts and serves /healthz run: | docker run -d --name smoke-test \ @@ -63,13 +54,10 @@ jobs: -sS -f -o /dev/null http://localhost:9222/healthz docker rm -f smoke-test - # Audit of this repo's own workflows; accepted findings are in - # .github/zizmor.yml. zizmor: uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1 - # Single stable name for the org's required-status-check ruleset to point - # at, regardless of how the real jobs above are split or renamed. + # The one name the ruleset requires, however the jobs above change. required-checks-passed: name: Required checks passed runs-on: ubuntu-latest diff --git a/.github/zizmor.yml b/.github/zizmor.yml index 5455cb9..e540ae0 100644 --- a/.github/zizmor.yml +++ b/.github/zizmor.yml @@ -1,18 +1,13 @@ -# zizmor configuration, read by the zizmor job in validate.yml. Anything accepted -# here is accepted on purpose -- each entry says why. - rules: unpinned-uses: config: policies: - # GitHub's own and the org's actions stay on tags (Dependabot moves - # them); third-party actions are SHA-pinned. + # GitHub's and our own actions on tags; third-party SHA-pinned. "actions/*": ref-pin "drumandbytes/*": ref-pin "*": hash-pin dangerous-triggers: ignore: - # workflow_run so Dependabot PRs get a token that can merge; never - # checks out PR code. + # Needed for Dependabot merges; never checks out PR code. - auto-merge.yml