Skip to content

Move the scaffold onto the shared reusable workflows - #466

Merged
oxyc merged 1 commit into
masterfrom
refactor/shared-workflows
Sep 7, 2026
Merged

oxyc merged 1 commit into
masterfrom
refactor/shared-workflows

Conversation

@oxyc

@oxyc oxyc commented Sep 7, 2026

Copy link
Copy Markdown
Member

This is the source of the problem, not another instance of it. Every repo generated from this scaffold inherits a vendored .github/actions/setup and PACKAGIST_GITHUB_TOKEN — which is why retiring the generoi-deploy machine user has meant visiting thirty-odd sites one at a time. Fixing it here stops new repos joining that queue.

File Becomes
test.yml test.yml@v2
deploy_production.yml / deploy_staging.yml deploy.yml@v2 + the local e2e wrapper
e2e.yml thin wrapper over e2e.yml@v2, still workflow_dispatch + workflow_call
vulnerability-scan.yml vulnerability-scan.yml@v2
.github/actions/setup deleted — superseded by setup@v2
.github/actions/install-wordpress deleted — the shared test workflow installs WP
.github/workflows/deploy.yml deleted — a subset of deploy.yml@v2

Net −249 lines, and Composer authenticates as genero-composer-bot with no PAT anywhere, so new projects start on a per-run token that expires in an hour rather than a machine user's non-expiring PAT.

The vulnerability scan is a real behaviour change

Worth calling out rather than burying. The scaffold's scan predated the shared one entirely: it ran wp vuln status and notified Microsoft Teams. The shared workflow runs composer audit --locked, notifies Google Chat, opens fix PRs via genero-vuln-bot, and gates the nightly cron on the repo's maintenance org property so unmaintained sites stop alerting.

That is what the rest of the fleet has run for months — the scaffold was the last thing still on the old one. If you'd rather keep Teams here, say so and I'll split it out.

What CI proves

CI: Test on this PR exercises the new test path with no PAT left to fall back on, so green means the app token genuinely works. The deploy path is workflow_dispatch-only; it is the same change proven green through production deploys on scata, wiidare, aktio-wordpress, kokkikartano.fi, mutti, bcplatformscom, lofs, medihealth, feelia, seafront and spfpension.

🤖 Generated with Claude Code

https://claude.ai/code/session_01PJ9rPCo5ZJbUPVS5dRGnZx

Every repo generated from this scaffold inherited a vendored setup action and
PACKAGIST_GITHUB_TOKEN, which is why the generoi-deploy retirement has had to
visit thirty-odd sites one at a time. Fixing it here stops the bleeding.

  test.yml                  -> test.yml@v2
  deploy_production.yml     -> deploy.yml@v2 (+ the local e2e wrapper)
  deploy_staging.yml        -> deploy.yml@v2 (+ the local e2e wrapper)
  e2e.yml                   -> a thin wrapper over e2e.yml@v2, still
                               workflow_dispatch + workflow_call
  vulnerability-scan.yml    -> vulnerability-scan.yml@v2
  .github/actions/setup     deleted, superseded by setup@v2
  .github/actions/install-wordpress  deleted, the shared test workflow does it
  .github/workflows/deploy.yml       deleted, a subset of deploy.yml@v2

Composer now authenticates as genero-composer-bot with no PAT anywhere, so new
projects start on a per-run token that expires in an hour instead of a machine
user's PAT.

The vulnerability scan is the biggest behaviour change: it predated the shared
scan entirely, running `wp vuln status` and notifying Microsoft Teams. The
shared workflow runs `composer audit --locked`, notifies Google Chat, opens
fix PRs via genero-vuln-bot, and gates on the repo's `maintenance` org property.
That is what the rest of the fleet has been running for months; the scaffold was
the last thing still on the old one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PJ9rPCo5ZJbUPVS5dRGnZx
@oxyc
oxyc merged commit ea63d0a into master Sep 7, 2026
1 check passed
@oxyc
oxyc deleted the refactor/shared-workflows branch September 7, 2026 15:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant