diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 9e804ca..ef2b7dc 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -7,36 +7,23 @@ on: jobs: auto-merge: - # The reusable workflow cannot grant itself more than the caller has, and - # the org default for GITHUB_TOKEN is read-only — so declare it here. + # The org default token is read-only. permissions: contents: write pull-requests: write - # Only the conclusion is checked, not workflow_run.event: a same-repo - # branch (which is how Dependabot and dnb-robot push) triggers CI as - # 'push', not 'pull_request', so gating on the event would silently skip - # every run. The reusable workflow looks up the PR itself and enforces - # the author allow-list, which is the actual safety gate; a run with no - # open PR just no-ops. + # Not gated on workflow_run.event: Dependabot branches run CI as 'push'. + # The reusable workflow's author check is the real gate. if: >- github.event.workflow_run.conclusion == 'success' && (github.event.workflow_run.actor.login == 'dependabot[bot]' || github.event.workflow_run.actor.login == 'dnb-robot[bot]') uses: drumandbytes/reusable-actions/.github/workflows/auto-merge.yml@v1 with: - # dnb-robot[bot] opens two different kinds of PR here now: release-please's - # own version-bump PR (patch/minor/major all possible - gate to patch - # only, same as eraser/music-router), and regenerate-track-maps' PR - # (never touches .release-please-manifest.json, so its version never - # changes base-to-head - trivially "a patch bump" every time, i.e. - # unconditional in practice, without needing its own allow-list entry). + # dnb-robot opens release-please PRs (patch-only) and track-map PRs, which + # never touch the manifest and so always count as patch. patch-only-authors: '["dnb-robot[bot]"]' - # release-please's merge needs to cascade into another release-please - # run (to actually cut the tag) and publish.yml's tag-triggered build - - # neither happens from a GITHUB_TOKEN-authored merge. + # A GITHUB_TOKEN merge triggers no workflows: no release, no publish.yml run. use-app-token-for-merge: true - # Only the two secrets the called workflow uses, rather than `inherit` - # handing it every repo and org secret. secrets: DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }} AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }} diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 488c5e2..0635978 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,9 +1,7 @@ name: CI on: - # push and pull_request both fired on every commit to an open PR (the same - # jobs twice) and push again on merge to master. One trigger covers PR - # branches, the same as the org's other repos. + # PR branches only, as in the org's other repos. push: branches-ignore: [master] workflow_dispatch: @@ -16,12 +14,10 @@ permissions: contents: read jobs: - # build, vet, gofmt and test, as the hand-written job did. test: uses: drumandbytes/reusable-actions/.github/workflows/go-ci.yml@v1 with: - # Explicit rather than read from go.mod: its `go 1.26.0` directive - # would install exactly 1.26.0, while "1.26" gets the latest 1.26.x. + # "1.26", not go.mod: `go 1.26.0` there would pin that exact patch. go-version: "1.26" # Never run here before; enable once its findings are triaged. run-golangci-lint: false @@ -41,14 +37,10 @@ jobs: file: Dockerfile push: false - # Audit of this repo's own workflows; accepted findings are in - # .github/zizmor.yml. zizmor: uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1 - # Single stable name for the org's required-status-check ruleset - # (protecting-main) to point at, regardless of how the real jobs above are - # split or renamed. + # The one name the ruleset requires, however the jobs above change. required-checks-passed: name: Required checks passed runs-on: ubuntu-latest diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 7daddfa..663c074 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,10 +1,6 @@ name: Publish image -# Triggered by a version tag push - normally release-please.yml pushing one -# automatically once its release PR is merged, or push one by hand: -# git tag v1.1.0 && git push origin v1.1.0. Either way, a deliberate release -# action, not every commit to master. Uses GITHUB_TOKEN for GHCR auth -# (packages: write below) - no separate secret to manage. +# Version tags, from release-please or pushed by hand. GITHUB_TOKEN covers GHCR. on: push: tags: diff --git a/.github/workflows/regenerate-track-maps.yml b/.github/workflows/regenerate-track-maps.yml index 48820a0..dd9bcc7 100644 --- a/.github/workflows/regenerate-track-maps.yml +++ b/.github/workflows/regenerate-track-maps.yml @@ -1,15 +1,11 @@ name: Regenerate track maps -# Monthly is a safety margin, not a real cadence requirement - track layouts -# only ever change between seasons. peter-evans/create-pull-request only -# opens/updates a PR when the script actually changed a file (plain `git -# status` under the hood), so a no-op month produces nothing to review. +# Monthly is a safety margin; layouts change between seasons. No change, no PR. on: schedule: - cron: "0 3 1 * *" workflow_dispatch: {} -# Read-only token; no job here writes to the repo or reads other scopes. permissions: contents: read @@ -28,17 +24,13 @@ jobs: - name: Generate track maps run: go run ./cmd/gentrackmaps - # Repo default GITHUB_TOKEN is read-only (org policy), and a PR opened - # with it needs a maintainer to manually approve the CI run before it - # can even start. dnb-robot is a recognized collaborator with write - # access, so a PR opened as it skips both problems - and unlike - # GITHUB_TOKEN-authored pushes, this one properly triggers CI/auto-merge. + # dnb-robot, not GITHUB_TOKEN: its PR triggers CI and auto-merge without + # manual approval. - uses: actions/create-github-app-token@v3 id: app_token with: client-id: ${{ secrets.DNB_ROBOT_CLIENT_ID }} private-key: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }} - # Only what this job needs (create-pull-request pushes a branch and opens a labelled PR), not the app's whole grant. permission-contents: write permission-pull-requests: write permission-issues: write diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 34ad4b1..20d37b4 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -11,8 +11,6 @@ permissions: jobs: release-please: uses: drumandbytes/reusable-actions/.github/workflows/release-please.yml@v1 - # Only the two secrets the called workflow uses, rather than `inherit` - # handing it every repo and org secret. secrets: DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }} AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }} diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index d706790..b65eb77 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -1,10 +1,6 @@ name: Security -# Trivy scan of the built image (base image, OS packages and the Go binary's -# modules), kept out of CI on purpose: auto-merge gates on CI's conclusion, -# so a scan there would let one vulnerability block every Dependabot merge. -# Findings still fail this workflow; the weekly run catches advisories -# published against what's already on master. +# Image scan. Separate from CI so a finding can't block auto-merge of an unrelated Dependabot fix. on: pull_request: branches: [master] diff --git a/.github/zizmor.yml b/.github/zizmor.yml index c9f6ee2..e540ae0 100644 --- a/.github/zizmor.yml +++ b/.github/zizmor.yml @@ -1,18 +1,13 @@ -# zizmor configuration, read by the zizmor job in ci.yml. Anything accepted -# here is accepted on purpose -- each entry says why. - rules: unpinned-uses: config: policies: - # GitHub's own and the org's actions stay on tags (Dependabot moves - # them); third-party actions are SHA-pinned. + # GitHub's and our own actions on tags; third-party SHA-pinned. "actions/*": ref-pin "drumandbytes/*": ref-pin "*": hash-pin dangerous-triggers: ignore: - # workflow_run so Dependabot PRs get a token that can merge; never - # checks out PR code. + # Needed for Dependabot merges; never checks out PR code. - auto-merge.yml