Repository navigation
Move the scaffold onto the shared reusable workflows - #466
Merged
Merged
Conversation
Every repo generated from this scaffold inherited a vendored setup action and
PACKAGIST_GITHUB_TOKEN, which is why the generoi-deploy retirement has had to
visit thirty-odd sites one at a time. Fixing it here stops the bleeding.
test.yml -> test.yml@v2
deploy_production.yml -> deploy.yml@v2 (+ the local e2e wrapper)
deploy_staging.yml -> deploy.yml@v2 (+ the local e2e wrapper)
e2e.yml -> a thin wrapper over e2e.yml@v2, still
workflow_dispatch + workflow_call
vulnerability-scan.yml -> vulnerability-scan.yml@v2
.github/actions/setup deleted, superseded by setup@v2
.github/actions/install-wordpress deleted, the shared test workflow does it
.github/workflows/deploy.yml deleted, a subset of deploy.yml@v2
Composer now authenticates as genero-composer-bot with no PAT anywhere, so new
projects start on a per-run token that expires in an hour instead of a machine
user's PAT.
The vulnerability scan is the biggest behaviour change: it predated the shared
scan entirely, running `wp vuln status` and notifying Microsoft Teams. The
shared workflow runs `composer audit --locked`, notifies Google Chat, opens
fix PRs via genero-vuln-bot, and gates on the repo's `maintenance` org property.
That is what the rest of the fleet has been running for months; the scaffold was
the last thing still on the old one.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PJ9rPCo5ZJbUPVS5dRGnZx
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is the source of the problem, not another instance of it. Every repo generated from this scaffold inherits a vendored
.github/actions/setupandPACKAGIST_GITHUB_TOKEN— which is why retiring thegeneroi-deploymachine user has meant visiting thirty-odd sites one at a time. Fixing it here stops new repos joining that queue.test.ymltest.yml@v2deploy_production.yml/deploy_staging.ymldeploy.yml@v2+ the local e2e wrappere2e.ymle2e.yml@v2, stillworkflow_dispatch+workflow_callvulnerability-scan.ymlvulnerability-scan.yml@v2.github/actions/setupsetup@v2.github/actions/install-wordpress.github/workflows/deploy.ymldeploy.yml@v2Net −249 lines, and Composer authenticates as
genero-composer-botwith no PAT anywhere, so new projects start on a per-run token that expires in an hour rather than a machine user's non-expiring PAT.The vulnerability scan is a real behaviour change
Worth calling out rather than burying. The scaffold's scan predated the shared one entirely: it ran
wp vuln statusand notified Microsoft Teams. The shared workflow runscomposer audit --locked, notifies Google Chat, opens fix PRs viagenero-vuln-bot, and gates the nightly cron on the repo'smaintenanceorg property so unmaintained sites stop alerting.That is what the rest of the fleet has run for months — the scaffold was the last thing still on the old one. If you'd rather keep Teams here, say so and I'll split it out.
What CI proves
CI: Teston this PR exercises the new test path with no PAT left to fall back on, so green means the app token genuinely works. The deploy path isworkflow_dispatch-only; it is the same change proven green through production deploys on scata, wiidare, aktio-wordpress, kokkikartano.fi, mutti, bcplatformscom, lofs, medihealth, feelia, seafront and spfpension.🤖 Generated with Claude Code
https://claude.ai/code/session_01PJ9rPCo5ZJbUPVS5dRGnZx