Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 6 additions & 19 deletions .github/workflows/auto-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,36 +7,23 @@ on:

jobs:
auto-merge:
# The reusable workflow cannot grant itself more than the caller has, and
# the org default for GITHUB_TOKEN is read-only — so declare it here.
# The org default token is read-only.
permissions:
contents: write
pull-requests: write
# Only the conclusion is checked, not workflow_run.event: a same-repo
# branch (which is how Dependabot and dnb-robot push) triggers CI as
# 'push', not 'pull_request', so gating on the event would silently skip
# every run. The reusable workflow looks up the PR itself and enforces
# the author allow-list, which is the actual safety gate; a run with no
# open PR just no-ops.
# Not gated on workflow_run.event: Dependabot branches run CI as 'push'.
# The reusable workflow's author check is the real gate.
if: >-
github.event.workflow_run.conclusion == 'success' &&
(github.event.workflow_run.actor.login == 'dependabot[bot]' ||
github.event.workflow_run.actor.login == 'dnb-robot[bot]')
uses: drumandbytes/reusable-actions/.github/workflows/auto-merge.yml@v1
with:
# dnb-robot[bot] opens two different kinds of PR here now: release-please's
# own version-bump PR (patch/minor/major all possible - gate to patch
# only, same as eraser/music-router), and regenerate-track-maps' PR
# (never touches .release-please-manifest.json, so its version never
# changes base-to-head - trivially "a patch bump" every time, i.e.
# unconditional in practice, without needing its own allow-list entry).
# dnb-robot opens release-please PRs (patch-only) and track-map PRs, which
# never touch the manifest and so always count as patch.
patch-only-authors: '["dnb-robot[bot]"]'
# release-please's merge needs to cascade into another release-please
# run (to actually cut the tag) and publish.yml's tag-triggered build -
# neither happens from a GITHUB_TOKEN-authored merge.
# A GITHUB_TOKEN merge triggers no workflows: no release, no publish.yml run.
use-app-token-for-merge: true
# Only the two secrets the called workflow uses, rather than `inherit`
# handing it every repo and org secret.
secrets:
DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }}
AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }}
14 changes: 3 additions & 11 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,7 @@
name: CI

on:
# push and pull_request both fired on every commit to an open PR (the same
# jobs twice) and push again on merge to master. One trigger covers PR
# branches, the same as the org's other repos.
# PR branches only, as in the org's other repos.
push:
branches-ignore: [master]
workflow_dispatch:
Expand All @@ -16,12 +14,10 @@ permissions:
contents: read

jobs:
# build, vet, gofmt and test, as the hand-written job did.
test:
uses: drumandbytes/reusable-actions/.github/workflows/go-ci.yml@v1
with:
# Explicit rather than read from go.mod: its `go 1.26.0` directive
# would install exactly 1.26.0, while "1.26" gets the latest 1.26.x.
# "1.26", not go.mod: `go 1.26.0` there would pin that exact patch.
go-version: "1.26"
# Never run here before; enable once its findings are triaged.
run-golangci-lint: false
Expand All @@ -41,14 +37,10 @@ jobs:
file: Dockerfile
push: false

# Audit of this repo's own workflows; accepted findings are in
# .github/zizmor.yml.
zizmor:
uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1

# Single stable name for the org's required-status-check ruleset
# (protecting-main) to point at, regardless of how the real jobs above are
# split or renamed.
# The one name the ruleset requires, however the jobs above change.
required-checks-passed:
name: Required checks passed
runs-on: ubuntu-latest
Expand Down
6 changes: 1 addition & 5 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,6 @@
name: Publish image

# Triggered by a version tag push - normally release-please.yml pushing one
# automatically once its release PR is merged, or push one by hand:
# git tag v1.1.0 && git push origin v1.1.0. Either way, a deliberate release
# action, not every commit to master. Uses GITHUB_TOKEN for GHCR auth
# (packages: write below) - no separate secret to manage.
# Version tags, from release-please or pushed by hand. GITHUB_TOKEN covers GHCR.
on:
push:
tags:
Expand Down
14 changes: 3 additions & 11 deletions .github/workflows/regenerate-track-maps.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,11 @@
name: Regenerate track maps

# Monthly is a safety margin, not a real cadence requirement - track layouts
# only ever change between seasons. peter-evans/create-pull-request only
# opens/updates a PR when the script actually changed a file (plain `git
# status` under the hood), so a no-op month produces nothing to review.
# Monthly is a safety margin; layouts change between seasons. No change, no PR.
on:
schedule:
- cron: "0 3 1 * *"
workflow_dispatch: {}

# Read-only token; no job here writes to the repo or reads other scopes.
permissions:
contents: read

Expand All @@ -28,17 +24,13 @@ jobs:
- name: Generate track maps
run: go run ./cmd/gentrackmaps

# Repo default GITHUB_TOKEN is read-only (org policy), and a PR opened
# with it needs a maintainer to manually approve the CI run before it
# can even start. dnb-robot is a recognized collaborator with write
# access, so a PR opened as it skips both problems - and unlike
# GITHUB_TOKEN-authored pushes, this one properly triggers CI/auto-merge.
# dnb-robot, not GITHUB_TOKEN: its PR triggers CI and auto-merge without
# manual approval.
- uses: actions/create-github-app-token@v3
id: app_token
with:
client-id: ${{ secrets.DNB_ROBOT_CLIENT_ID }}
private-key: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }}
# Only what this job needs (create-pull-request pushes a branch and opens a labelled PR), not the app's whole grant.
permission-contents: write
permission-pull-requests: write
permission-issues: write
Expand Down
2 changes: 0 additions & 2 deletions .github/workflows/release-please.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,6 @@ permissions:
jobs:
release-please:
uses: drumandbytes/reusable-actions/.github/workflows/release-please.yml@v1
# Only the two secrets the called workflow uses, rather than `inherit`
# handing it every repo and org secret.
secrets:
DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }}
AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }}
6 changes: 1 addition & 5 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,6 @@
name: Security

# Trivy scan of the built image (base image, OS packages and the Go binary's
# modules), kept out of CI on purpose: auto-merge gates on CI's conclusion,
# so a scan there would let one vulnerability block every Dependabot merge.
# Findings still fail this workflow; the weekly run catches advisories
# published against what's already on master.
# Image scan. Separate from CI so a finding can't block auto-merge of an unrelated Dependabot fix.
on:
pull_request:
branches: [master]
Expand Down
9 changes: 2 additions & 7 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -1,18 +1,13 @@
# zizmor configuration, read by the zizmor job in ci.yml. Anything accepted
# here is accepted on purpose -- each entry says why.

rules:
unpinned-uses:
config:
policies:
# GitHub's own and the org's actions stay on tags (Dependabot moves
# them); third-party actions are SHA-pinned.
# GitHub's and our own actions on tags; third-party SHA-pinned.
"actions/*": ref-pin
"drumandbytes/*": ref-pin
"*": hash-pin

dangerous-triggers:
ignore:
# workflow_run so Dependabot PRs get a token that can merge; never
# checks out PR code.
# Needed for Dependabot merges; never checks out PR code.
- auto-merge.yml
Loading