Skip to content

Configurable Laravel and Node CI, self-check CI, workflow guide - #1

Merged
PavlosIsaris merged 6 commits into
mainfrom
ci-workflows-v0.1
Sep 30, 2026
Merged

PavlosIsaris merged 6 commits into
mainfrom
ci-workflows-v0.1

Conversation

@PavlosIsaris

Copy link
Copy Markdown
Contributor

First releasable state of the shared workflows, to be tagged as v0.1.

CI workflows

  • laravel-ci.yml and node-ci.yml run parallel jobs (static checks, tests, build, optional Playwright tests) and report one aggregate ci / CI check.
  • Each tool is auto-detected, or replaced by lint-command, types-command or test-command. coverage-file turns on the Codecov upload. working-directory supports an application in a subfolder.
  • Setup steps are shared between jobs with YAML anchors, so a branch test runs the branch code.
  • New Node CI template. Both templates list every input with its default and example values.

Security

  • scan-dev-configs fails on any script in .vscode, .claude, .cursor or .idea unless allowed-scripts lists it.
  • Fixed: both composite actions failed under bash -e when grep found no match.
  • The organisation requires SHA-pinned actions, including our own. security.yml now checks out scify/.github at job.workflow_sha and runs its actions from a local path.
  • Dependabot now also updates the pins inside .github/actions/*.

Removed

  • license-check.yml and owasp-dependency-check.yml.

Documentation

  • New workflow guide in .github/workflows/README.md: how a call works, every input with example values, recipes, troubleshooting.
  • The README states the scope: public CI and shared configuration only. Deployment workflows go to private repositories.

Self-check

  • actionlint and shellcheck on workflows, templates and composite actions.
  • The guide must document every input, and internal references must use one tag.
  • The composite actions must pass on good fixtures and fail on bad ones.
  • security.yml, laravel-ci.yml and node-ci.yml run against this repository and the fixture projects in tests/fixtures/.

Nobody uses the licence check. For PHP and npm, OWASP Dependency-Check adds
little over composer audit and npm audit, and its Composer analyzer is
experimental and was not enabled.
- Split into parallel lint, test, build and optional browser test jobs,
  with one aggregate CI check for branch protection
- Auto-detect tools, or run lint-command, types-command, test-command
- Optional Codecov upload with coverage-file
- working-directory for applications in a subfolder
- Share setup steps between jobs with YAML anchors
- Document accepted values in every input description
- Add the Node CI template; list every input in both templates
- scan-dev-configs: fail on any script file (extension, executable bit or
  shebang) unless allowed-scripts lists it
- Fix both actions failing under bash -e when grep finds no match
- security.yml: the org requires SHA-pinned actions, so check out
  scify/.github at job.workflow_sha and run the actions from a local path
- security.yml: add allowed-dev-scripts
The guide explains how to call each workflow, lists every input with
example values, and gives recipes and troubleshooting. The README states
that deployment workflows belong in a private repository.
- actionlint and shellcheck on workflows, templates and composite actions
- The workflow guide must document every input
- Internal references must use one release tag
- Composite actions must pass on good fixtures and fail on bad ones
- security.yml, laravel-ci.yml and node-ci.yml run against this
  repository and the fixtures in tests/fixtures
@PavlosIsaris
PavlosIsaris merged commit ed05f2e into main Sep 30, 2026
24 checks passed
@PavlosIsaris
PavlosIsaris deleted the ci-workflows-v0.1 branch September 30, 2026 08:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant